| <!DOCTYPE html> |
| |
| |
| <!-- |
| | Generated by Apache Maven Doxia Site Renderer 2.0.0 from src/site/markdown/release-process.md at 2026-05-18 |
| | Rendered using Apache Maven Fluido Skin 2.0.0-M11 |
| --> |
| <html xmlns="http://www.w3.org/1999/xhtml" lang="en"> |
| <head> |
| <meta charset="UTF-8" /> |
| <meta name="viewport" content="width=device-width, initial-scale=1" /> |
| <meta name="generator" content="Apache Maven Doxia Site Renderer 2.0.0" /> |
| <title>Release Process – Apache Axis2</title> |
| <link rel="stylesheet" href="./css/apache-maven-fluido-2.0.0-M11.min.css" /> |
| <link rel="stylesheet" href="./css/site.css" /> |
| <link rel="stylesheet" href="./css/print.css" media="print" /> |
| <script src="./js/apache-maven-fluido-2.0.0-M11.min.js"></script> |
| </head> |
| <body> |
| <div class="container-fluid container-fluid-top"> |
| <header> |
| <div id="banner"> |
| <div class="pull-left"><div id="bannerLeft"><h1><a href="https://www.apache.org/"><img class="class java.lang.Object" src="https://www.apache.org/images/asf_logo_wide.png" /> Apache Axis2</a></h1></div></div> |
| <div class="pull-right"><div id="bannerRight"><h1><a href="https://axis.apache.org/axis2/java/core/"><img class="class java.lang.Object" src="https://axis.apache.org/axis2/java/core/images/axis.jpg" /></a></h1></div></div> |
| <div class="clear"><hr/></div> |
| </div> |
| |
| <div id="breadcrumbs"> |
| <ul class="breadcrumb"> |
| <li id="publishDate">Last Published: 2026-05-17<span class="divider">|</span> |
| </li> |
| <li id="projectVersion">Version: 2.0.1<span class="divider">|</span></li> |
| <li><a href="https://www.apache.org" class="externalLink">Apache</a><span class="divider">/</span></li> |
| <li><a href="index.html">Axis2/Java</a><span class="divider">/</span></li> |
| <li class="active">Release Process</li> |
| </ul> |
| </div> |
| </header> |
| <div class="row-fluid"> |
| <header id="leftColumn" class="span2"> |
| <nav class="well sidebar-nav"> |
| <ul class="nav nav-list"> |
| <li class="nav-header">Axis2/Java</li> |
| <li><a href="index.html">Home</a></li> |
| <li><a href="download.html">Downloads</a></li> |
| <li><a href="javascript:void(0)"><span class="icon-chevron-down"></span>Release Notes</a> |
| <ul class="nav nav-list"> |
| <li><a href="release-notes/1.6.1.html">1.6.1</a></li> |
| <li><a href="release-notes/1.6.2.html">1.6.2</a></li> |
| <li><a href="release-notes/1.6.3.html">1.6.3</a></li> |
| <li><a href="release-notes/1.6.4.html">1.6.4</a></li> |
| <li><a href="release-notes/1.7.0.html">1.7.0</a></li> |
| <li><a href="release-notes/1.7.1.html">1.7.1</a></li> |
| <li><a href="release-notes/1.7.2.html">1.7.2</a></li> |
| <li><a href="release-notes/1.7.3.html">1.7.3</a></li> |
| <li><a href="release-notes/1.7.4.html">1.7.4</a></li> |
| <li><a href="release-notes/1.7.5.html">1.7.5</a></li> |
| <li><a href="release-notes/1.7.6.html">1.7.6</a></li> |
| <li><a href="release-notes/1.7.7.html">1.7.7</a></li> |
| <li><a href="release-notes/1.7.8.html">1.7.8</a></li> |
| <li><a href="release-notes/1.7.9.html">1.7.9</a></li> |
| <li><a href="release-notes/1.8.0.html">1.8.0</a></li> |
| <li><a href="release-notes/1.8.1.html">1.8.1</a></li> |
| <li><a href="release-notes/1.8.2.html">1.8.2</a></li> |
| <li><a href="release-notes/2.0.0.html">2.0.0</a></li> |
| <li><a href="release-notes/2.0.1.html">2.0.1</a></li> |
| </ul></li> |
| <li><a href="modules/index.html">Modules</a></li> |
| <li><a href="tools/index.html">Tools</a></li> |
| <li class="nav-header">Documentation</li> |
| <li><a href="docs/toc.html">Table of Contents</a></li> |
| <li><a href="docs/installationguide.html">Installation Guide</a></li> |
| <li><a href="docs/quickstartguide.html">QuickStart Guide</a></li> |
| <li><a href="docs/userguide.html">User Guide</a></li> |
| <li><a href="docs/jaxws-guide.html">JAXWS Guide</a></li> |
| <li><a href="docs/pojoguide.html">POJO Guide</a></li> |
| <li><a href="docs/spring.html">Spring Guide</a></li> |
| <li><a href="docs/webadminguide.html">Web Administrator's Guide</a></li> |
| <li><a href="docs/migration.html">Migration Guide (from Axis1)</a></li> |
| <li class="nav-header">Resources</li> |
| <li><a href="faq.html">FAQ</a></li> |
| <li><a href="https://github.com/apache/axis-axis2-java-core" class="externalLink">Source Code</a></li> |
| <li class="nav-header">Get Involved</li> |
| <li><a href="overview.html">Overview</a></li> |
| <li><a href="mail-lists.html">Mailing Lists</a></li> |
| <li class="active"><a>Release Process</a></li> |
| <li><a href="guidelines.html">Developer Guidelines</a></li> |
| <li><a href="siteHowTo.html">Build the Site</a></li> |
| <li class="nav-header">Project Information</li> |
| <li><a href="https://github.com/apache/axis-axis2-java-core/graphs/contributors" class="externalLink">Contributors</a></li> |
| <li><a href="https://issues.apache.org/jira/projects/AXIS2/issues" class="externalLink">Issues</a></li> |
| <li class="nav-header">Apache</li> |
| <li><a href="https://www.apache.org/licenses/LICENSE-2.0.html" class="externalLink">License</a></li> |
| <li><a href="https://www.apache.org/foundation/sponsorship.html" class="externalLink">Sponsorship</a></li> |
| <li><a href="https://www.apache.org/foundation/thanks.html" class="externalLink">Thanks</a></li> |
| <li><a href="https://www.apache.org/security/" class="externalLink">Security</a></li> |
| </ul> |
| </nav> |
| <div class="well sidebar-nav"> |
| <div id="poweredBy"> |
| <div class="clear"></div> |
| <div class="clear"></div> |
| <a href="https://maven.apache.org/" class="builtBy" target="_blank"><img class="builtBy" alt="Built by Maven" src="./images/logos/maven-feather.png" /></a> |
| </div> |
| </div> |
| </header> |
| <main id="bodyColumn" class="span10"> |
| <!-- |
| ~ Licensed to the Apache Software Foundation (ASF) under one |
| ~ or more contributor license agreements. See the NOTICE file |
| ~ distributed with this work for additional information |
| ~ regarding copyright ownership. The ASF licenses this file |
| ~ to you under the Apache License, Version 2.0 (the |
| ~ "License"); you may not use this file except in compliance |
| ~ with the License. You may obtain a copy of the License at |
| ~ |
| ~ http://www.apache.org/licenses/LICENSE-2.0 |
| ~ |
| ~ Unless required by applicable law or agreed to in writing, |
| ~ software distributed under the License is distributed on an |
| ~ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY |
| ~ KIND, either express or implied. See the License for the |
| ~ specific language governing permissions and limitations |
| ~ under the License. |
| --> |
| <section><a id="Release_Process"></a> |
| <h1>Release Process</h1><section><a id="Release_process_overview"></a> |
| <h2>Release process overview</h2><section><a id="Update.3A_Since_the_1.8.x_series_we_have_released_from_git_master_without_branches._Skip_to_Performing_a_Release._We_may_or_may_not_use_branches_again_in_the_future."></a> |
| <h3>Update: Since the 1.8.x series we have released from git master without branches. Skip to Performing a Release. We may or may not use branches again in the future.</h3></section><section><a id="Cutting_a_branch"></a> |
| <h3>Cutting a branch</h3> |
| <ul> |
| |
| <li> |
| <p>When a release is ready to go, release manager (RM) puts |
| forward a release plan as per standard Apache process, including |
| dates. This gets VOTEd on by the committers. During this period the |
| trunk is still the only relevant source base.</p></li> |
| <li> |
| <p>As soon as a release is approved (or even before), RM should |
| add the new version into JIRA as a target.</p></li> |
| <li> |
| <p>At the point where we would normally do the “code freeze” for a |
| release, the RM cuts a branch named for the release. This branch is |
| where the release candidates and releases will happen.</p></li> |
| <li> |
| <p>Ideally a release branch is only around for a week or maybe two |
| before the release happens.</p></li> |
| <li> |
| <p>The only things that should EVER get checked into the release |
| branch are - 1) bug fixes targeted at the release, 2) |
| release-specific updates (documentation, SNAPSHOT removal, etc). In |
| particular new functionality does not go here unless it is a |
| solution to a JIRA report targeted at the release.</p></li> |
| <li> |
| <p>Normal development continues on the trunk.</p></li> |
| </ul></section><section><a id="Dependencies_and_branches"></a> |
| <h3>Dependencies and branches</h3> |
| <ul> |
| |
| <li> |
| <p>The trunk should always be “cutting edge” and as such should |
| usually be pointing at SNAPSHOT versions of all dependencies. This |
| allows for continuous integration with our partner projects.</p></li> |
| <li> |
| <p>Soon after a release branch is cut, the RM is responsible for |
| removing ALL dependencies on SNAPSHOT versions and replacing them |
| with officially released versions. This change happens only on the |
| release branch.</p></li> |
| </ul></section><section><a id="Managing_change_and_issue_resolution_with_a_release_branch"></a> |
| <h3>Managing change and issue resolution with a release branch</h3> |
| <ul> |
| |
| <li> |
| <p>The RM goes through JIRA issues and sets “fix for” to point to |
| both “NIGHTLY” and the new branched release number for the fixes |
| that are targeted for the release after the branch is cut.</p></li> |
| <li> |
| <p>In general, the assignee/coder fixes JIRA issues or makes other |
| changes <em>on the trunk</em>. If the JIRA issue is targeted at the |
| release, or upon coder's discretion, they then merge the fix over |
| to the release branch.</p></li> |
| <li> |
| <p>This way the trunk is ALWAYS up-to-date, and we don't have to |
| worry about losing fixes that have only been made on the release |
| branch.</p></li> |
| <li> |
| <p>When the assignee resolves an issue, they confirm it's been |
| fixed in both branches, if appropriate.</p></li> |
| </ul></section><section><a id="Checking_changes_into_the_branch"></a> |
| <h3>Checking changes into the branch</h3> |
| <ul> |
| |
| <li> |
| <p>If bug fixes are needed later for a release which has long |
| since happened (to fix user issues, etc), those fixes generally |
| should also happen on the trunk first assuming the problem still |
| exists on the trunk.</p></li> |
| <li> |
| <p>There are only two cases where we would ever check anything |
| into the branch without first checking it into the trunk. 1) |
| Release specific items (release number references, release notes, |
| removal of SNAPSHOTs), and 2) if the trunk has moved on in some |
| incompatible way.</p></li> |
| </ul></section></section><section><a id="Performing_a_release"></a> |
| <h2>Performing a release</h2><section><a id="Preparation"></a> |
| <h3>Preparation</h3> |
| <p>Verify that the code meets the basic requirements for being releasable:</p> |
| <ol style="list-style-type: decimal;"> |
| |
| <li> |
| <p>Check that the set of legal (<code>legal/*.LICENSE</code>) files corresponds to the set of third party |
| JARs included in the binary distribution.</p></li> |
| <li> |
| <p>Check that the <code>apache-release</code> profile works correctly and produces the required distributions. |
| The profile can be executed as follows:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">mvn clean install -Papache-release |
| </code></pre></li> |
| </ol> |
| <p>You may also execute a dry run of the release process: mvn release:prepare -DdryRun=true. In a dry run, the generated zip files will still be labled as SNAPSHOT. After this, you need to clean up using the following command: mvn release:clean</p> |
| <ol style="list-style-type: decimal;"> |
| |
| <li>Check that the Maven site can be generated and deployed successfully, and that it has the expected content.</li> |
| </ol> |
| <p>To generate the entire documentation in one place, complete with working inter-module links, execute the site-deploy phase (and check the files under target/staging). A quick and reliable way of doing that is to use the following command: mvn -Dmaven.test.skip=true clean package site-deploy</p> |
| <ol style="list-style-type: decimal;"> |
| |
| <li> |
| <p>Check that the source distribution is buildable.</p></li> |
| <li> |
| <p>Check that the source tree is buildable with an empty local Maven repository.</p></li> |
| </ol> |
| <p>If any problems are detected, they should be fixed on the trunk (except for issues specific to the |
| release branch) and then merged to the release branch.</p> |
| <p>Next update the release note found under <code>src/site/markdown/release-notes</code>. To avoid extra work for |
| the RM doing the next major release, these changes should be done on the trunk first and then merged |
| to the release branch.</p></section><section><a id="Pre-requisites"></a> |
| <h3>Pre-requisites</h3> |
| <p>The following things are required to perform the actual release:</p> |
| <ul> |
| |
| <li> |
| <p>A PGP key that conforms to the <a href="http://www.apache.org/dev/release-signing.html" class="externalLink">requirements for Apache release signing</a>. |
| To make the release process easier, the passphrase for the code signing key should |
| be configured in <code>${user.home}/.m2/settings.xml</code>:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode"><settings> |
| ... |
| <profiles> |
| <profile> |
| <id>apache-release</id> |
| <properties> |
| <gpg.passphrase><!-- key passphrase --></gpg.passphrase> |
| </properties> |
| </profile> |
| </profiles> |
| ... |
| </settings> |
| </code></pre></li> |
| <li> |
| <p>The release process uses a Nexus staging repository. Every committer should have access to the corresponding |
| staging profile in Nexus. To validate this, login to <a href="https://repository.apache.org" class="externalLink">repository.apache.org</a> |
| and check that you can see the <code>org.apache.axis2</code> staging profile. The credentials used to deploy to Nexus |
| should be added to <code>settings.xml</code>:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode"><servers> |
| ... |
| <server> |
| <id>apache.releases.https</id> |
| <username><!-- ASF username --></username> |
| <password><!-- ASF LDAP password --></password> |
| </server> |
| ... |
| </servers> |
| </code></pre></li> |
| </ul></section><section><a id="Release"></a> |
| <h3>Release</h3> |
| <p>In order to prepare the release artifacts for vote, execute the following steps:</p> |
| <p>If not yet done, export your public key and <a href="https://dist.apache.org/repos/dist/release/axis/axis2/java/core/KEYS" class="externalLink"> append it there. </a></p> |
| <p>If not yet done, also export your public key to the dev area and <a href="https://dist.apache.org/repos/dist/dev/axis/axis2/java/core/KEYS" class="externalLink"> append it there. </a></p> |
| <p>The command to export a public key is as follows:</p> |
| <p><code>gpg –armor –export key_id</code></p> |
| <p>If you have multiple keys, you can define a ~/.gnupg/gpg.conf file for a default. Note that while ‘gpg –list-keys’ will show your public keys, using maven-release-plugin with the command ‘release:perform’ below requires ‘gpg –list-secret-keys’ to have a valid entry that matches your public key, in order to create ‘asc’ files that are used to verify the release artifcats. ‘release:prepare’ creates the sha512 checksum files.</p> |
| <ol style="list-style-type: decimal;"> |
| |
| <li> |
| <p>Start the release process using the following command - use ‘mvn release:rollback’ to undo and be aware that in the main pom.xml there is an apache parent that defines some plugin versions<a href="https://maven.apache.org/pom/asf/" class="externalLink"> documented here. </a></p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">mvn release:prepare |
| </code></pre> |
| <p>When asked for a tag name, accept the default value (in the following format: <code>vX.Y.Z</code>).</p></li> |
| <li> |
| <p>Perform the release using the following command - though be aware you cannot rollback as shown above after that. That may need to happen if there are site problems further below. To start over, see the “Recovering from a failed release” section below.</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">mvn release:perform |
| |
| The created artifacts i.e. zip files can be checked with, for example, 'sha512sum axis2-2.0.0-bin.zip' which should match the generated axis2-2.0.0-bin.zip.sha512 file. In that example, use 'gpg --verify axis2-2.0.0-bin.zip.asc axis2-2.0.0-bin.zip' to verify the artifacts were signed correctly. |
| </code></pre></li> |
| <li> |
| <p>Login to Nexus and close the staging repository. For more details about this step, see |
| <a href="https://maven.apache.org/developers/release/maven-project-release-procedure.html" class="externalLink">here</a> and <a href="https://infra.apache.org/publishing-maven-artifacts.html#promote" class="externalLink">here</a>.</p></li> |
| <li> |
| <p>Execute the <code>target/checkout/etc/dist.py</code> script to upload the source and binary distributions to the development area of the <a href="https://dist.apache.org/repos/dist/" class="externalLink"> repository. </a></p></li> |
| <li> |
| <p>Create a staging area for the Maven site:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">git clone https://gitbox.apache.org/repos/asf/axis-site.git |
| cd axis-site |
| cp -r axis2/java/core/ axis2/java/core-staging |
| git add axis2/java/core-staging |
| git commit -am "create core-staging dir as a prerequisite for the publish-scm plugin" |
| git push |
| </code></pre></li> |
| <li> |
| <p>Change to the <code>target/checkout</code> directory and prepare the site using the following commands:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">mvn site-deploy |
| mvn scm-publish:publish-scm -Dscmpublish.skipCheckin=true |
| </code></pre> |
| <p>Now go to the <code>target/scmpublish-checkout</code> directory (relative to <code>target/checkout</code>) and check that there are no unexpected changes to the site. Then commit the changes.</p> |
| <p>Update: This plugin has a problem with specifying the remote core-staging dir, created above, with the git URL. See <a href="https://issues.apache.org/jira/browse/MSITE-1033" class="externalLink">https://issues.apache.org/jira/browse/MSITE-1033</a> . For now, copy the output of the scmpublish-checkout dir listed above to the core-staging dir created earlier in this doc.</p> |
| <p>The root dir of axis-site has a .asf.yaml file, referenced here at target/scmpublish-checkout/.asf.yaml, that is <a href="https://github.com/apache/infrastructure-asfyaml/blob/main/README.md" class="externalLink"> documented here. </a></p></li> |
| <li> |
| <p>Start the release vote by sending a mail to <code>java-dev@axis.apache.org</code>. |
| The mail should mention the following things:</p> |
| <ul> |
| |
| <li>A link to the Nexus staging repository.</li> |
| <li>A link to the directory containing the distributions |
| (<a href="https://dist.apache.org/repos/dist/dev/axis/axis2/java/core/x.y.x/" class="externalLink">https://dist.apache.org/repos/dist/dev/axis/axis2/java/core/x.y.x/</a>).</li> |
| <li>A link to the preview of the Maven site (<a href="https://axis.apache.org/axis2/java/core-staging/" class="externalLink">https://axis.apache.org/axis2/java/core-staging/</a>).</li> |
| </ul></li> |
| </ol> |
| <p>If the vote passes, execute the following steps:</p> |
| <ol style="list-style-type: decimal;"> |
| |
| <li> |
| <p>Promote the artifacts in the staging repository. See |
| <a href="https://central.sonatype.org/publish/release/#close-and-drop-or-release-your-staging-repository" class="externalLink">here</a> |
| for detailed instructions for this step.</p></li> |
| <li> |
| <p>Publish the distributions:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">svn mv https://dist.apache.org/repos/dist/dev/axis/axis2/java/core/x.y.z \ |
| https://dist.apache.org/repos/dist/release/axis/axis2/java/core/ |
| </code></pre></li> |
| <li> |
| <p>Publish the site:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">git clone https://gitbox.apache.org/repos/asf/axis-site.git |
| git rm -r core |
| git mv core-staging core |
| git commit -am "Axis2 X.Y.Z site" |
| git push |
| </code></pre></li> |
| </ol> |
| <p>It may take several hours before everything has been synchronized. Before proceeding, check that</p> |
| <ul> |
| |
| <li>the Maven artifacts for the release are available from the Maven central repository;</li> |
| <li>the Maven site has been synchronized;</li> |
| <li>the distributions can be downloaded from the mirror sites.</li> |
| </ul> |
| <p>Once everything is in place, send announcements to <code>java-user@axis.apache.org</code> (with copy to |
| <code>java-dev@axis.apache.org</code>) and <code>announce@apache.org</code>. Since the two lists have different conventions, |
| audiences and moderation policies, it is recommended to send the announcement separately to the two lists. |
| Note that mail to <code>announce@apache.org</code> must be sent from an <code>apache.org</code> address and will |
| always be moderated. The announcement sent to <code>announce@apache.org</code> also should include a general description |
| of Axis2, because not everybody subscribed to that list knows about the project.</p></section><section><a id="Post-release_actions"></a> |
| <h3>Post-release actions</h3> |
| <ol style="list-style-type: decimal;"> |
| |
| <li> |
| <p>Update the DOAP file (<code>etc/doap_Axis2.rdf</code>) and add a new entry for the release.</p></li> |
| <li> |
| <p>Update the status of the release version in JIRA.</p></li> |
| <li> |
| <p>Remove old (archived) releases from <a href="https://dist.apache.org/repos/dist/release/axis/axis2/java/core/" class="externalLink">https://dist.apache.org/repos/dist/release/axis/axis2/java/core/</a>.</p></li> |
| <li> |
| <p>Create an empty release note for the next release under <code>src/site/markdown/release-notes</code>.</p></li> |
| </ol></section><section><a id="Branch_protection_.28.asf.yaml.29"></a> |
| <h3>Branch protection (<code>.asf.yaml</code>)</h3> |
| <p>The repository has ASF-mandated branch protection rules in <code>.asf.yaml</code> that prevent |
| force-push and branch deletion on <code>master</code> and <code>release/*</code> branches. This is a supply |
| chain security measure applied across all ASF repositories (see PR #1200).</p> |
| <p>Under normal development, these rules are transparent — regular <code>git push</code> works as |
| before. The protection only matters during release recovery (see below).</p></section><section><a id="Recovering_from_a_failed_release"></a> |
| <h3>Recovering from a failed release</h3> |
| <p>If <code>mvn release:prepare</code> or <code>mvn release:perform</code> fails and you need to start over, |
| the recovery requires <code>git push --force</code> which is blocked by branch protection.</p> |
| <p><strong>Recovery procedure:</strong></p> |
| <ol style="list-style-type: decimal;"> |
| |
| <li> |
| <p>Temporarily disable force-push protection by editing <code>.asf.yaml</code> — remove or |
| comment out <code>restrict_force_push: true</code>. Commit and push this change:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode"># Edit .asf.yaml to remove restrict_force_push: true |
| git add .asf.yaml |
| git commit -m "Temporarily disable force-push protection for release recovery" |
| git push |
| </code></pre> |
| <p>Wait a minute for the GitHub ruleset to update.</p></li> |
| <li> |
| <p>Perform the recovery:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">git reset --hard <last-commit-before-release-started> |
| git push --force |
| git push --delete origin vX.Y.Z |
| </code></pre></li> |
| <li> |
| <p><strong>Immediately restore protection</strong> by reverting the <code>.asf.yaml</code> change:</p> |
| |
| <pre class="prettyprint"><code class="nohighlight nocode">git revert HEAD~1 # reverts the .asf.yaml disable commit |
| git push |
| </code></pre> |
| <p><strong>Do not skip this step.</strong> The risk of leaving force-push unprotected (credential |
| compromise, accidental history rewrite) is higher than the inconvenience of the |
| toggle. If the <code>.asf.yaml</code> change is accidentally included in a release commit, |
| force-push protection will be silently disabled until someone notices.</p></li> |
| <li> |
| <p>Verify protection is restored: check the repository Settings → Rules → Rulesets |
| page on GitHub to confirm force-push is blocked again.</p></li> |
| </ol> |
| <p><strong>Why not just leave force-push enabled?</strong> The ASF infrastructure team rolled out |
| branch protection across all repositories after supply chain attacks (xz-utils, 2024) |
| demonstrated the risk of history rewriting in open source projects. If a committer's |
| credentials are compromised, force-push protection prevents an attacker from rewriting |
| master to inject malicious code. The Axis2 project accepts this tradeoff: a small |
| inconvenience during rare release failures in exchange for continuous protection |
| against a real threat.</p> |
| <p><strong>Known issue:</strong> The Maven site plugin has a bug with Git SCM URLs (MSITE-1033, |
| status: IN PROGRESS) that can cause site deployment failures during the release |
| process. This is a separate issue from branch protection but can compound the need |
| for release restarts.</p></section></section></section> </main> |
| </div> |
| </div> |
| <hr/> |
| <footer> |
| <div class="container-fluid"> |
| <div class="row-fluid"> |
| <p>© 2004–2026 |
| <a href="https://www.apache.org/">The Apache Software Foundation</a> |
| </p> |
| </div> |
| </div> |
| </footer> |
| </body> |
| </html> |