Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Improves CVE tasks

...

  1. Add a news item to the main page of the OFBiz website: http://ofbiz.apache.org/index.html
  2. Add the information about the release to the OFBiz download page: http://ofbiz.apache.org/download.html
  3. Create an html page with the release notes (generated by Jira)
    1. In Jira, mark the version as "released" and create a new version for the next release
  4. Add the information about the release to the release history page: http://www.apache.org/dist/ofbiz/
  5. Send an announcement to the user, dev and announce@apache.org lists
  6. Update related files

    http://ofbiz.apache.org/download.html
    http://ofbiz.apache.org/source-repositories.html
    https://github.com/apache/ofbiz-site/blob/master/doap_OFBiz.rdf
    Please complete the list if necessary...

  7. Update the release informations on other sites: OFBiz on other sites
  8. If it's an EOL release announce using one of the files at https://svn.apache.org/repos/private/pmc/ofbiz/security/EOL-Drafts
  9. If the release embeds a CVE (ie a fix for a security vulnerabilty)
    1. Send the OSS Email and ASF Email emails and set the CVE as public
    2. Complete the CVE information at https://cveprocess.apache.org/cve5, notably the reference using 'vendor-advisory' tag for pointer to ASF mailing list announcement once public
    3. Send the OSS Email and ASF Email emails and set the CVE as public
    4. Update the security page on site
    5. Transform the related Jira to a security issue
      1. Set it as a OFBIZ-1525 subtask
      2. Change the title by beginning with [SECURITY] (CVE-AAAA-cveNumber)

Creating a new release branch

...