Re: [VOTE] Release Apache Commons JEXL 3.6.3 based on RC2

Rob Tompkins <[email protected]> Tue, 23 Jun 2026 13:22:56 -0400
Newsgroups gmane.comp.jakarta.commons.devel
Message-ID <[email protected]>
+1 all looks good to me signatures all loook correct, the site looks =
good, the reports all look good, the work underpinning the release looks =
good. builds on 11,17,21,25. Release-Notes good too.

Go

> On Jun 20, 2026, at 10:53=E2=80=AFAM, Gary Gregory =
<[email protected]> wrote:
>=20
> We have fixed a few bugs and added enhancements since the release of
> Apache Commons JEXL 3.6.2, so I would like to release Apache Commons
> JEXL 3.6.3.
>=20
> Apache Commons JEXL 3.6.3 RC2 is available for review here:
>    https://dist.apache.org/repos/dist/dev/commons/jexl/3.6.3-RC2 (svn
> revision 85346)
>=20
> The Git tag commons-jexl-3.6.3-RC2 commit for this RC is
> 22c9343c1221b96f9c452ca35a657873610a05c8, which you can browse here:
>    =
https://gitbox.apache.org/repos/asf?p=3Dcommons-jexl.git;a=3Dcommit;h=3D22=
c9343c1221b96f9c452ca35a657873610a05c8
> You may checkout this tag using:
>    git clone https://gitbox.apache.org/repos/asf/commons-jexl.git
> --branch commons-jexl-3.6.3-RC2 commons-jexl-3.6.3-RC2
>=20
> Maven artifacts are here:
>    =
https://repository.apache.org/content/repositories/orgapachecommons-1950/o=
rg/apache/commons/commons-jexl3/3.6.3/
>=20
> These are the artifacts and their hashes:
>=20
> #Release SHA-512s
> #Sat Jun 20 14:43:52 UTC 2026
> =
commons-jexl-3.6.3-bin.tar.gz=3D5d218237d78a2844456a9f290465aa01ab9634221a=
8bdaba4e6dc6954fc1c661cf8009b0b75bd4112a84532da8585af8b76e92f56cd853e81b63=
5f99e86c279b
> =
commons-jexl-3.6.3-bin.zip=3D5b6be2aad828824f1bf00dede1688cbbab5001c8d4f42=
cd781c462e2a7ec252a9f934c2e45d055580c92e2670eb9d3576733a1219783cb6fcf4c55f=
3d261d3a9
> =
commons-jexl-3.6.3-src.tar.gz=3D1fec6494a26bcb2c98d25a644f1fc3c59af733a5c7=
1022b816fb4a65a9356a1f3a67639b7ca037df24fc9bb6aa6c249c3e83bc94489531b6f629=
ebfe13739f3e
> =
commons-jexl-3.6.3-src.zip=3D0a1204d1eb6647707574b4c2e6be47c390cdef59af4c0=
2cf51313bdd6dd72dc58a3a994fad23c8d7bcf9f4e1ac042f25f5d6c1f541e9fe7eb733f90=
43bb89fe6
> =
commons-jexl3-3.6.3-bom.json=3D476d36bc338fd408b71f6cc92ea83008fc1588a803b=
5e9b2928b30cac7bb732c483f3fbb2bf4c3f268f3c13a73cf03a8156c7cc92337ce818e452=
3f09ea47df7
> =
commons-jexl3-3.6.3-bom.xml=3Da7adc2e32dc6a60aae5279fce8a137055232712f66c7=
7adca83f1ff0a2765c204d0256f1fea20776d54684a1762082a6c163b3cdf43e04208924b2=
5c4fd6454d
> =
commons-jexl3-3.6.3-javadoc.jar=3Dade7659986bb50035c2abe8a963de757928dc8f6=
b5d843cb9b5045163128ea6e84cbee350ac407863a5e36cb888b43e78f8786755de29399ea=
88e5f8a9dafb9e
> =
commons-jexl3-3.6.3-sources.jar=3D4d2967a30ca7c4389ad5f7cf0001654e8f6607da=
370b2699078541057f22a3d22a5b0cdb5ac03508cea656f350147467922a8bccdb2f783c6a=
aab2d205c59549
> =
commons-jexl3-3.6.3-test-sources.jar=3D55d98a4afb526c211475865d629df369a06=
616dded2bae8a32550e7c231c5afbea00464da74f16cdd1a2a736ec8db9ca9f10e6b4dafb7=
4a1779f801519dfc436
> =
commons-jexl3-3.6.3-tests.jar=3D9557d9ae7342474e493f0abbb6c9267ac10968de51=
fc4b417be20b53e29a09a6f4a7fd0c8cb4864ddf1eec59185ff87c3a61a808d564ce2beafb=
1318e1dca6e0
> =
org.apache.commons_commons-jexl3-3.6.3.spdx.json=3D5c0cc93e95a366f25061919=
6a797aa15083d0c6e7f24ea9e63f249e5c4f0bd81f5173305bc7076b7900e6ca3e18573bcc=
357196a8e0aebd3994846d4f2949045
>=20
>=20
>=20
> I have tested this with 'mvn' and 'mvn clean install site' using:
>=20
> openjdk version "21.0.11" 2026-04-21
> OpenJDK Runtime Environment Homebrew (build 21.0.11)
> OpenJDK 64-Bit Server VM Homebrew (build 21.0.11, mixed mode, sharing)
>=20
> Apache Maven 3.9.16 (2bdd9fddda4b155ebf8000e807eb73fd829a51d5)
> Maven home: /opt/homebrew/Cellar/maven/3.9.16/libexec
> Java version: 21.0.11, vendor: Homebrew, runtime:
> =
/opt/homebrew/Cellar/openjdk@21/21.0.11/libexec/openjdk.jdk/Contents/Home
> Default locale: en_US, platform encoding: UTF-8
> OS name: "mac os x", version: "26.5.1", arch: "aarch64", family: "mac"
>=20
> Darwin Garys-MacBook-Pro.local 25.5.0 Darwin Kernel Version 25.5.0:
> Mon Apr 27 20:41:15 PDT 2026;
> root:xnu-12377.121.6~2/RELEASE_ARM64_T6041 arm64
>=20
> Docker version 29.4.3, build 055a478
>=20
>=20
> Details of changes since 3.6.2 are in the release notes:
>    =
https://dist.apache.org/repos/dist/dev/commons/jexl/3.6.3-RC2/RELEASE-NOTE=
S.txt
>    =
https://dist.apache.org/repos/dist/dev/commons/jexl/3.6.3-RC2/site/changes=
.html
>=20
> Site:
>    =
https://dist.apache.org/repos/dist/dev/commons/jexl/3.6.3-RC2/site/index.h=
tml
>    (Note some *relative* links are broken and the 3.6.3 directories
> are not yet created - these will be OK once the site is deployed.)
>=20
> JApiCmp Report (compared to 3.6.2):
>    =
https://dist.apache.org/repos/dist/dev/commons/jexl/3.6.3-RC2/site/japicmp=
.html
>=20
> RAT Report:
>    =
https://dist.apache.org/repos/dist/dev/commons/jexl/3.6.3-RC2/site/rat-rep=
ort.html
>=20
> KEYS:
>  https://downloads.apache.org/commons/KEYS
>=20
> Please review the release candidate and vote.
> This vote will close no sooner than 72 hours from now.
>=20
>  [ ] +1 Release these artifacts
>  [ ] +0 OK, but...
>  [ ] -0 OK, but really should fix...
>  [ ] -1 I oppose this release because...
>=20
> Thank you,
>=20
> Gary Gregory,
> Release Manager (using key 530AA5F25C25011F)
>=20
> The following is intended as a helper and refresher for reviewers.
>=20
> Validating a release candidate
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D
>=20
> These guidelines are NOT complete.
>=20
> Requirements: Git, Java, and Maven.
>=20
> You can validate a release from a release candidate (RC) tag as =
follows.
>=20
> 1a) Download and decompress the source archive from:
>=20
> https://dist.apache.org/repos/dist/dev/commons/jexl/3.6.3-RC2/source
>=20
> 1b) Check out the RC tag from git (optional)
>=20
> This is optional,  as a reviewer must at least check source =
distributions.
>=20
> git clone https://gitbox.apache.org/repos/asf/commons-jexl.git
> --branch commons-jexl-3.6.3-RC2 commons-jexl-3.6.3-RC2
> cd commons-jexl-3.6.3-RC2
>=20
> 2) Checking the build
>=20
> All components should include a default Maven goal, such that you can
> run 'mvn' from the command line by itself.
>=20
> 2) Check Apache licenses
>=20
> This step is not required if the site includes a RAT report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
>=20
> mvn apache-rat:check
>=20
> 3) Check binary compatibility
>=20
> This step is not required if the site includes a JApiCmp report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
>=20
> mvn verify -DskipTests -P japicmp japicmp:cmp
>=20
> 4) Build the package
>=20
> This check should be included in the default Maven build, but you can
> check it with:
>=20
> mvn -V clean package
>=20
> You can record the Maven and Java version produced by -V in your VOTE =
reply.
> To gather OS information from a command line:
> Windows: ver
> Linux: uname -a
>=20
> 4b) Check reproducibility
>=20
> To check that a build is reproducible, run:
>=20
> mvn clean verify artifact:compare -DskipTests
> =
-Dreference.repo=3Dhttps://repository.apache.org/content/repositories/stag=
ing/
> '-Dbuildinfo.ignore=3D*/*.spdx.json'
>=20
> Note that this excludes SPDX files from the check.
>=20
> 5) Build the site for a single module project
>=20
> Note: Some plugins require the components to be installed instead of =
packaged.
>=20
> mvn site
> Check the site reports in:
> - Windows: target\site\index.html
> - Linux: target/site/index.html
>=20
> -the end-
>=20
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>=20