5.1. Compose phase
Up: 5. Making releases
Prev: 5. Making releases
Next: 5.1.1. Uploading files
Pages:
5.1.1.Uploading files5.1.2.Checks5.1.3.License checks5.1.4.SBOM workflows
Sections:
Overview
The compose phase is where a Release Candidate is built up from its parts. The Release Manager assembles the Release Artifacts, uploads them to ATR, and runs the platform's checks against them. Composing is deliberately iterative: the Release Manager can add, replace, and remove artifacts, and re-run the checks, until the candidate is ready to put to a vote. The candidate is held in ATR throughout, and nothing is committed to the Apache distribution servers until the finish phase.
For a step by step walkthrough of this phase with screenshots, see the Compose section of the tutorial.
Responsibilities
The compose phase is mostly the work of the Release Manager, on behalf of the PMC:
- Assemble the release artifacts and upload them to the candidate. The ways of doing so are listed under How files reach ATR.
- Sign each artifact and register the corresponding key, so that ATR and, later, end users can verify the signatures. See Signing artifacts, and Release managers for the keys and access methods available to you.
- Run the checks and resolve anything they report before starting a vote.
Other PMC members are not required to act during compose, but the candidate is visible to them, and it is good practice to review it before it goes to a vote.
How files reach ATR
There are many ways to get files into a candidate:
- upload through the browser,
- upload over rsync,
- import from the committee's
dist/devarea in SVN, - upload with
atrCLI (Trusted Releases Client), - upload with ATR Maven Plugin,
- upload from a GitHub Actions workflow using Trusted Publishing.
Uploading files gives the commands and setup for each of these, and explains how each change to a candidate is recorded as a revision.
The SVN dist/dev import is one option among others, and we expect most release managers not to
need it. See The earlier dist/dev workflow for
the background.
Checks and compliance
ATR runs a number of automated checks over the composed artifacts to catch problems early, while they are still cheap to fix. These cover the integrity of the artifacts, their licensing, and the software bill of materials where one is provided:
- Checks - the checks ATR runs and how to read their results.
- License checks - how ATR helps you follow ASF licensing policy.
- SBOM workflows - generating and attaching a software bill of materials.
Most check results are there to help you produce a candidate that the PMC can vote on with confidence, and you can keep iterating whatever they report. A blocker, though, means that a mandatory policy condition has been violated, and the candidate cannot proceed to a vote until it is resolved.