Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

ASF produces releases in the form of source materials.  However "convenience" compiled versions may also be distributed https://www.apache.org/legal/release-policy.html#compiled-packages but as this becomes more common, along with container and other distributions, we need a better policy around builds, more infra to allow projects to do builds on ASF controlled infrastructure, etc.  See for example

Jira
serverASF JIRA
serverId5aa69414-a9e9-3523-82ec-879b028fb15b
keyASFP-23

Related to this are dependencies. We do sometimes include these in source distributions but it becomes more of an issue when they're in builds, containers etc too.  Figure out some dependency tracking stuff, such as SLSA (then we'd end up with formulas for builds as well as dependency tracking) https://slsa.dev/provenance/v0.2

...