buildAndPushRelease.py silently skips creating signatures for artifacts if wrong gpg keystore password is given [LUCENE-7448]
Open
legacy-jira-priority:Major
type:bug
- Dominant language
- Java
- Stars
- 3.6k
- Forks
- 1.4k
- Avg merge
- 2d 11h
- Merged PRs (30d)
- 88
Description
---
Migrated from [LUCENE-7448](https://issues.apache.org/jira/browse/LUCENE-7448) by Shalin Shekhar Mangar (@shalinmangar)
Contributor guide
Research direction
Open buildAndPushRelease.py and inspect how it handles an incorrect GPG keystore password while creating artifact signatures. Reproduce the reported case and verify that signature creation is no longer silently skipped, then validate the release workflow with the project's existing checks.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- release
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100