gpg artifact signing is difficult [LUCENE-5581]
- Dominant language
- Java
- Stars
- 3.6k
- Forks
- 1.4k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 88
Description
This task does not e.g. detect when you typo your password (after the password input), instead it just fails on each artifact.
this really sucks, because building a release is slow. so you lose a half hour or so if you typo a single character.
---
Migrated from [LUCENE-5581](https://issues.apache.org/jira/browse/LUCENE-5581) by Robert Muir (@rmuir)
Contributor guide
Research direction
No files, tests, or entry points are named. Start by locating the release artifact-signing workflow and its password handling, then reproduce a mistyped-password build to understand the current failure path. Done should mean an incorrect password is detected before every artifact is built and the release fails promptly with a clear message.
Written by the indexing model from the issue text.
Assessment
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100