Release Guide
This page describes the steps that a Cayenne Release Manager needs to perform to prepare a release. The specifics of Cayenne release process is that we are publishing both downloadable assemblies and Maven artifacts, so we have to build and publish things twice. Both forms of Cayenne release are also available for evaluation during the vote.
Prerequisites
- A release manager must have his public key appended to the KEYS file checked in to source control and the key published on one of the public key servers. More info can be found at https://www.apache.org/dev/release-signing.html
- Make sure “apache-releases” repository is configured in ~/.m2/settings.xml and an appropriate password is setup. See this page for details.
- Cayenne 5.0 requires Java 21, so the release must be built with JDK 21 or newer.
Preparing Sources
- Edit
UPGRADE.mdif there is anything to add there. (Notes for 4.2 and older live in a separateUPGRADE-4.2-and-older.mdand are normally left untouched.) - Update
RELEASE-NOTES.txtwith actual release name and current date as a release date. - Check Sources Compliance with RAT. The Apache RAT Maven plugin
is already configured in Cayenne:
cd cayenne mvn apache-rat:checkRat writes the report to
target/rat.txt. Read it and fix any issues. Prefer adding a missing license header over adding an exclusion;
when an exclusion really is warranted it goes intobuild-tools/rat-excludes.
Tagging the Repo and Releasing Maven Artifacts
-
Create a Git tag and Create Maven Staging Repository:
cd cayenne mvn release:clean mvn release:prepare -DpreparationGoals="clean install" -DautoVersionSubmodules=true mvn release:perform -P release [-Dgpg.keyname=B8AF90BF]The
releaseprofile (namedgpgprior to 5.0-M4) does two things: it GPG-signs the artifacts, and it attaches a-sources.jarand a-javadoc.jar. -
Close the staging repo. Login to https://repository.apache.org/ with Apache ID/password, go to “Staging Repositories” page. Select a staging repository that was just created during “mvn release:perform”, click “Close”. Take a note of the freshly created staging repository URL. It will be used by the people voting on Cayenne. It may look like this: https://repository.apache.org/content/repositories/orgapachecayenne-052/
Releasing Downloadable Assemblies
-
Switch to the release tag created above.
git clone https://github.com/apache/cayenne.git --branch "XXX" --depth 1 -
Build source package (it will be the basis for the binary packages built in the next steps) :
mvn clean install -Passembly,src -
Build binary assemblies. Release manager may skip running unit tests from here, as shown below, although release evaluators should use the src assembly for unit testing and other kinds of testing. For further details on a general Cayenne build process check this page.
-
Take “cayenne-assembly/target/cayenne-XXX-src.tar.gz”, unpack it somewhere, and perform binary builds from the unpacked directory (NOT FROM GIT CHECKOUT).
-
Per Apache release guidelines there shouldn’t be any binaries in a release, so you need manually copy Gradle wrapper. Just copy cayenne-gradle-plugin/gradle folder to the corresponding folder in unpacked sources.
cp -r ./cayenne-gradle-plugin/gradle ./cayenne-assembly/target/cayenne-XXX-src/cayenne-gradle-plugin/ -
Build binary artifacts
mvn clean package -Passembly,generic -DskipTests # You will need to do this on OS X mvn clean package -Passembly,mac -DskipTests # You will need to do this on Windows mvn clean package -Passembly,windows -DskipTests
-
-
Signing assemblies
You can find additional information in official Apache Release Distribution policy and on this page. Release manager key must be in the project KEYS file. Signing is a manual procedure not included in the Ant or Maven script. Here is how it might work ("-u” option can be omitted if you have only one GPG key):
# repeat for every assembly: cayenne-X.X-src.tar.gz, cayenne-X.X.tar.gz (generic), # cayenne-X.X-win.zip and cayenne-X.X-macosx.dmg gpg -a -b -u B8AF90BF cayenne-X.X.tar.gz gpg --print-md SHA512 cayenne-X.X.tar.gz > cayenne-X.X.tar.gz.sha512 -
Assemblies, signature and checksum files are committed to the special SVN repo used for staging development releases: https://dist.apache.org/repos/dist/dev/cayenne/. Use a separate folder for each release. For more info on this repository check the infrastructure docs.
Voting
- The vote is started on the dev mailing list.
- All committers are encouraged to vote on releases. Committer votes will be considered by the PMC (particularly -1 votes will be discussed) when making the final decision, but are not binding.
- Each PMC member will do the following before voting on a release:
- download the artifacts
- verify GPG signature and sha512 checksum
- satisfy themselves that the source matches the appropriate Git tag. This can be done by diffing the source against a recent git checkout.
- satisfy themselves that the Apache licensing requirements are met (this will usually be achieved by ensuring that all notices are in place and verifying that the source matches Git since all commits to Git are possible only if the committer has a CLA on file).
- satisfy themselves that the binary distribution is sane and passes basic usability tests. For example, that the Cayenne Modeler runs and the main jar passes some basic tests.
- satisfy themselves that the source passes agreed unit tests (either by running them manually or verifying that CI service has run those tests against the equivalent source).
Publishing the Release
-
Publish Maven artifacts. Go back to https://repository.apache.org/, select the staging repo and click “Release”.
-
Publish downloadable assemblies by moving them to the release repo:
svn mv https://dist.apache.org/repos/dist/dev/cayenne/X.X \ https://dist.apache.org/repos/dist/release/cayenne/
After the release
-
Delete a previous version of Cayenne release of the same branch from the dist server. It should be already [archived by Apache] (https://www.apache.org/dev/release.html#when-to-archive). Do this with an svn command like this:
svn rm https://dist.apache.org/repos/dist/release/cayenne/Y.Y -
Tell Jira that the release has been released. Ensure there is another milestone or release target already created for further work, but this was probably already done when a branch was created in preparation for release.
-
If the release is significant, consider press releases to relevant news sources
-
Review the main website pages (front page and why-cayenne especially) to add any new features
-
Add new cayenne version and a news item to the Cayenne web site (see CMS Guide)
-
Send an email to the Cayenne user and developer lists
-
Send a notification email to announce(at)apache.org
Troubleshooting
-
Retrying a failed step.
release:preparerecords the last completed phase inrelease.propertiesand resumes from there, so after a transient failure just run it again (-Dresume=falsestarts over).release:performwipes and re-creates target/checkout on every run, so it can be re-run as is. Check and drop the half-filled staging repo in Nexus before retryingrelease:perform. -
Undoing an attempt.
release:rollbackrestores the backup POMs, commits the revert and deletes the tag:mvn release:rollbackIt only works between
prepareandperform: a successfulrelease:performfinishes by callingrelease:clean, which deletes the release.properties and pom.xml.releaseBackup that rollback needs. A failedperformleaves them in place, so rollback still works there. Rollback cleans up after itself too, so it is a one-shot.It knows nothing about Nexus or SVN: drop the staging repo by hand. Tag removal only logs a warning if it fails, so verify it:
git ls-remote --tags originOn
STABLE-4.2(maven-release-plugin 2.5.3) the tag is never removed - tag removal was only implemented in 3.0.0-M1 - so delete it manually there. -
Nothing left to roll back, i.e.
performsucceeded but the release must be redone: drop the staging repo, then clean up the tag and the two[maven-release-plugin]commits by hand.git tag -d X.X && git push --delete origin X.X -
Nexus won’t close the staging repo. “Missing Signature”, or missing sources / javadoc, means
-P releasewas not active. Drop the repo and re-runmvn release:perform -P release. -
GPG can’t sign. Export
GPG_TTY=$(tty)so the agent can prompt for the passphrase, and pass-Dgpg.keynameif you have more than one key. Thegpg.passphraseproperty is deprecated in maven-gpg-plugin 3.2.x - use the agent or theMAVEN_GPG_PASSPHRASEenvironment variable. -
release:preparerefuses to start on local modifications: commit theRELEASE-NOTES.txtandUPGRADE.mdedits first.
Reference:
- Apache release publishing: https://www.apache.org/dev/release-publishing.html
- Apache Maven release publishing: https://www.apache.org/dev/publishing-maven-artifacts.html
- Apache RAT: https://creadur.apache.org/rat/
- Signing Releases: https://www.apache.org/dev/release-signing.html