Details
-
Bug
-
Status: Open
-
Normal
-
Resolution: Unresolved
-
None
-
None
-
Normal
Description
Currently, the release artifact build process does full maven upload of gpg-signed artifacts and package builds with repo signing. It would be helpful to be able to build and tag as a committer, then have the gpg signing as a separate event/process. The builds could be local and staged somewhere, then a release manager could verify and gpg sign the artifacts.
Attachments
Issue Links
- relates to
-
CASSANDRA-14970 New releases must supply SHA-256 and/or SHA-512 checksums
-
- Resolved
-