apache / apache/lucene

gpg artifact signing is difficult [LUCENE-5581]

Open
#6,643 1 comment 0 reactions 0 assignees View on GitHub
legacy-jira-priority:Major type:bug
Dominant language
Java
Stars
3.6k
Forks
1.4k
Avg merge
2d 11h
Merged PRs (30d)
88

Description

This task does not e.g. detect when you typo your password (after the password input), instead it just fails on each artifact.

this really sucks, because building a release is slow. so you lose a half hour or so if you typo a single character.

---
Migrated from [LUCENE-5581](https://issues.apache.org/jira/browse/LUCENE-5581) by Robert Muir (@rmuir)

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by locating the release artifact-signing workflow and its password handling, then reproduce a mistyped-password build to understand the current failure path. Done should mean an incorrect password is detected before every artifact is built and the release fails promptly with a clear message.

Written by the indexing model from the issue text.

Assessment

Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.