)]}'
{
  "log": [
    {
      "commit": "f840821c9a0a44df45fcf6bc0d84ad2c449052db",
      "tree": "42afe107da0ae229d6463d0b22c3c923bb736737",
      "parents": [
        "4e629909e14181193226502f2072cb89bee829f2",
        "2b7da201f79dac1ca2b155d54459635912424870"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Aug 25 22:23:28 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 25 22:23:28 2026 +0200"
      },
      "message": "Merge pull request #57 from apache/bugfix/SLING-13320-nexus-error-response\n\nSLING-13320 - handle a staging repository that no longer exists"
    },
    {
      "commit": "2b7da201f79dac1ca2b155d54459635912424870",
      "tree": "42afe107da0ae229d6463d0b22c3c923bb736737",
      "parents": [
        "4e629909e14181193226502f2072cb89bee829f2"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Aug 25 21:07:54 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Aug 25 21:50:50 2026 +0200"
      },
      "message": "SLING-13320 - handle a staging repository that no longer exists\n\nfinalize promotes the staging repository in step 2 and Nexus drops it on\nrelease, so the website step in step 6 searched a repository that was\nalready gone. Nexus answers that with an HTML error page, which parsed as\nJSON only produced \"MalformedJsonException at line 2 column 4\" and, being\nunchecked, took down the whole run after every irreversible step had\nalready succeeded.\n\n* RepositoryService.getArtifacts checks the response status and reports\n  the failure as an IOException naming the repository\n* UpdateLocalSiteCommand falls back to the released POMs on\n  dist.apache.org when the staged ones cannot be read\n* FinalizeCommand treats the repository as gone once it has promoted it,\n  and the website step no longer lets an unchecked exception fail\n  finalize\n\nThe mock Nexus now answers an unknown repository the way the real one\ndoes, so the regression test reproduces the reported exception exactly.\n"
    },
    {
      "commit": "4e629909e14181193226502f2072cb89bee829f2",
      "tree": "7108dc29f5321fc5fb0cb57e4c8f128e7cbe554b",
      "parents": [
        "81ed59158936ae16aa273d523c4b2d2601640afb",
        "b2909bd9183e8f7237f1629150adfddeab469a47"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 24 17:18:47 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 17:18:47 2026 +0200"
      },
      "message": "Merge pull request #55 from apache/feature/drop-third-party-docker-actions\n\nRemove third-party GitHub Actions from docker-push workflow and fix double image build"
    },
    {
      "commit": "81ed59158936ae16aa273d523c4b2d2601640afb",
      "tree": "2e9a5a146c8b03e79ea63070b3fbc78d59beb948",
      "parents": [
        "7400a9019528c1a1de8762dfe36ba0f49cc7f023",
        "7369d1473c1c93f5f3c432cdb0993f0037be8f37"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 24 17:18:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 17:18:29 2026 +0200"
      },
      "message": "Merge pull request #54 from apache/feature/SLING-12146-windows-build\n\nSLING-12146 - fix the Windows build"
    },
    {
      "commit": "7400a9019528c1a1de8762dfe36ba0f49cc7f023",
      "tree": "20ac02a11eddb4f2899f946219c438584b7e3652",
      "parents": [
        "8cc6e1807d51cc21a7ebcd49d2cf0cc2cf9d589a"
      ],
      "author": {
        "name": "Radu Cotescu",
        "email": "radu@apache.org",
        "time": "Mon Aug 24 16:29:45 2026 +0200"
      },
      "committer": {
        "name": "Radu Cotescu",
        "email": "radu@apache.org",
        "time": "Mon Aug 24 16:29:50 2026 +0200"
      },
      "message": "trivial: quote positional arguments\n"
    },
    {
      "commit": "8cc6e1807d51cc21a7ebcd49d2cf0cc2cf9d589a",
      "tree": "2c342a4f7573eccf6af2ec47d2b3fcf84bd4365b",
      "parents": [
        "ba852b805fa4919a70ba810d14e6d711da51bf15"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 24 16:28:33 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 24 16:28:33 2026 +0200"
      },
      "message": "SLING-13314 - do not sign the commits the CLI creates (#53)\n\nJGit reads commit.gpgsign from the ambient git config, but only jgit core is on the\nclasspath and it registers no SignerFactory, so any committer who signs their commits\nhit UnsupportedSigningFormatException in all five places the tool commits.\n\nThe container holds no key material and every commit the tool has ever made is\nunsigned, so ask for that explicitly rather than inheriting whatever the host config\nsays. The resulting commit object is unchanged."
    },
    {
      "commit": "b2909bd9183e8f7237f1629150adfddeab469a47",
      "tree": "57a6602abafbca58c30e3797e41d3defee140301",
      "parents": [
        "ba852b805fa4919a70ba810d14e6d711da51bf15"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Thu Aug 20 21:56:56 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Thu Aug 20 22:01:36 2026 +0200"
      },
      "message": "Remove third-party GitHub Actions from docker-push workflow and fix double image build\n\nThe publish workflow pinned three docker/* actions by SHA, each of which must\nappear on the ASF org-level allowlist. Approved SHAs get a three-month expiry\nonce a newer version is approved and are then removed automatically, so every\npin needs periodic bumping -- and a stale pin fails as a silent \"Startup\nfailure\" with no logs (see ba852b8). All three turn out to be unnecessary:\n\n* docker/setup-buildx-action was never used. docker-maven-plugin creates its own\n  docker-container builder named \"maven\" and passes --builder maven to every\n  buildx invocation; the runner-level builder the action created was torn down\n  unused (run 32298804318). buildx itself is preinstalled on the runner at\n  /usr/libexec/docker/cli-plugins/docker-buildx.\n* docker/setup-qemu-action is replaced by the binfmt container it runs\n  internally. Emulation is genuinely required -- the arm64 stage runs apk,\n  jlink and java -Xshare:dump.\n* docker/login-action is replaced by docker login --password-stdin.\n  docker-maven-plugin resolves credentials from ~/.docker/config.json, which is\n  exactly what the action writes.\n\nThat leaves only actions/checkout and actions/setup-java, implicitly trusted as\nactions/* and needing no SHA pinning.\n\nAlso stop building the image twice. Run 32298804318 shows docker:build at the\npackage phase running\n\n  buildx build --platform linux/amd64 ... --load\n\nand docker:push then running\n\n  buildx build --platform linux/amd64,linux/arm64 ... --push\n\nwith the first image discarded. -Ddocker.buildArchiveOnly\u003dtrue skips it while\nstill producing target/docker/**/tmp/docker-build.tar, which\nBuildXService.push() extracts as the push build context.\n-Ddocker.skip.build\u003dtrue would not work: BuildMojo returns before the archive\nis created, leaving docker:push with no context (verified locally against\ndocker-maven-plugin 0.48.1).\n"
    },
    {
      "commit": "7369d1473c1c93f5f3c432cdb0993f0037be8f37",
      "tree": "cc61f53b2dd0292ee2331df642a4a1f7fc2b063a",
      "parents": [
        "fece945075abb99e8981160f41795a00df7143f3"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Thu Aug 20 21:44:09 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Thu Aug 20 21:44:09 2026 +0200"
      },
      "message": "SLING-12146 - skip the image build on Windows, and address the Sonar finding\n\nThe Windows run of PR #54 got through the whole test suite (183 tests, 0 failures,\n0 errors), confirming the three fixes, and then failed building the container image:\n\n    Unable to pull \u0027azul/zulu-openjdk-alpine:21\u0027 :\n    no matching manifest for windows/amd64 10.0.17763 in the manifest list entries\n\nThe Dockerfile is FROM alpine, so a Windows docker daemon cannot pull the base image\nat all; this is not something the Windows build can be made to do. Skip it there via\ndocker.skip so Windows keeps compiling and running the tests, and leave producing the\nimage to the Linux build.\n\nAlso switches the artifactFiles collector to Stream.toList() (java:S6204). The\nemptyDirectories list below it is reversed in place, so that one stays mutable.\n"
    },
    {
      "commit": "fece945075abb99e8981160f41795a00df7143f3",
      "tree": "5ff132e26ca6aa0343b7c55d99d3a39e339e1aa7",
      "parents": [
        "ba852b805fa4919a70ba810d14e6d711da51bf15"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Thu Aug 20 21:24:52 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Thu Aug 20 21:26:27 2026 +0200"
      },
      "message": "SLING-12146 - fix the Windows build\n\nThree separate causes behind the nine failures in the log attached to the issue:\n\n- No .gitattributes, so Git for Windows\u0027 default core.autocrlf\u003dtrue rewrote the\n  fixtures on checkout. That broke the two tests that hash and PGP-verify a .pom\n  byte-for-byte, and the three that compare generated mail against LF-only text\n  blocks. Reproduced by converting the resources to CRLF locally.\n\n- JBakeContentUpdater used Files.write(Path, Iterable), which terminates lines with\n  the platform separator. On Windows that rewrote every line of the LF-only site\n  sources, so update-local-site would have pushed a whole-file diff to the website\n  rather than the intended change.\n\n- downloadFileFromRepository never closed the stream it wrote each artifact to,\n  leaking a descriptor per file. On Windows the open handle leaves the directory\n  entry in place after the delete, which is the DirectoryNotEmptyException the\n  issue reports.\n\nAlso drops the operatingSystems pin added as a workaround in #24, so the Windows\nbuild runs again and can confirm the fix.\n"
    },
    {
      "commit": "ba852b805fa4919a70ba810d14e6d711da51bf15",
      "tree": "ce0ed532ad6600b5b01a39447f61fe506d971803",
      "parents": [
        "cc62920d9aa30885b6b3a4f3c2539639e8447702"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 19 22:29:26 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 19 22:29:26 2026 +0200"
      },
      "message": "Fix unapproved docker/setup-buildx-action and setup-qemu-action SHA in GH workflows - #665 (#52)\n\nThe pinned SHAs for docker/setup-buildx-action and setup-qemu-action were dropped from the ASF INFRA GitHub Actions allowlist, causing docker-push.yml to fail with startup_failure.\n\nRepin to the currently approved SHAs."
    },
    {
      "commit": "cc62920d9aa30885b6b3a4f3c2539639e8447702",
      "tree": "35b1fc99162621c796bc22d8b8092d82169ed976",
      "parents": [
        "597a0428289a4f701292542492ed69bc3403c9aa",
        "1e069ed53f9718067cc5f6d334337f3e968fa5c4"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Tue Aug 18 21:36:24 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 18 21:36:24 2026 +0200"
      },
      "message": "Merge pull request #48 from apache/feature/SLING-13253-site-shallow-clone\n\nSLING-13253 - update-local-site: shallow-clone the site checkout"
    },
    {
      "commit": "1e069ed53f9718067cc5f6d334337f3e968fa5c4",
      "tree": "35b1fc99162621c796bc22d8b8092d82169ed976",
      "parents": [
        "597a0428289a4f701292542492ed69bc3403c9aa"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 20:52:13 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Aug 18 21:30:46 2026 +0200"
      },
      "message": "SLING-13253 - update-local-site: shallow-clone the site checkout\n\nThe checkout is cloned inside the container, so unless it is pointed at a\ndirectory that outlives the run it is re-cloned every time - a full clone of\nsling-site is ~380MB of history against ~15MB of content. Only the tip of the\npublished branch is ever needed: the content is edited and committed on top of\nit, never inspected historically. The clone is therefore shallow and\nsingle-branch, which brings it down to ~25MB, and the refresh fetch stays\nshallow so a reused checkout does not grow back into a full clone.\n\nCovered by a test that runs against a real JGit and two real local repositories\nrather than mocking git: it clones shallowly, refreshes, commits and pushes, so\na JGit upgrade that breaks shallow fetches, or a server that refuses a push from\na shallow clone, fails here rather than during a release.\n"
    },
    {
      "commit": "597a0428289a4f701292542492ed69bc3403c9aa",
      "tree": "30d4c1359ae96e7f040ef42985dad94cb24f02cf",
      "parents": [
        "e2a0d700f715ef6884823c9900a1c57b3deef145",
        "a6afb9ab33ff4ac21880018c84a647db6f29724f"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Tue Aug 18 21:12:01 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 18 21:12:01 2026 +0200"
      },
      "message": "Merge pull request #50 from apache/feature/SLING-13253-site-update-fixes\n\nSLING-13253 - update-local-site: fix problems found running the website update"
    },
    {
      "commit": "e2a0d700f715ef6884823c9900a1c57b3deef145",
      "tree": "924199ac64f71a0ac4b514ed5ff3b38fb27f83fc",
      "parents": [
        "209fa6967af7465f2b65963dc8de8bbdda10bf87",
        "3abc65ed48fec3137a7634dd8368001da5d1d64e"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Tue Aug 18 21:11:41 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 18 21:11:41 2026 +0200"
      },
      "message": "Merge pull request #51 from apache/feature/SLING-13289-complete-image-rename\n\nSLING-13289 - complete the Docker image rename"
    },
    {
      "commit": "3abc65ed48fec3137a7634dd8368001da5d1d64e",
      "tree": "924199ac64f71a0ac4b514ed5ff3b38fb27f83fc",
      "parents": [
        "209fa6967af7465f2b65963dc8de8bbdda10bf87"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 21:24:35 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 21:24:35 2026 +0200"
      },
      "message": "SLING-13289 - complete the Docker image rename\n\nThree references to the old apache/sling-cli image were left behind. The one\nthat matters is CommandProcessor: it sets picocli\u0027s program name, so every usage\nmessage the tool prints told the user to run an image that no longer exists.\nrun.sh had the same problem, and two README examples were missed because they\nwere added while the rename was in flight.\n"
    },
    {
      "commit": "a6afb9ab33ff4ac21880018c84a647db6f29724f",
      "tree": "8ad2e79fe620e6f09789d32259e8571891fcf0e1",
      "parents": [
        "2d5b7e9f89b9aec172d4d545741b5b247cb9eb4b"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 21:19:17 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 21:20:35 2026 +0200"
      },
      "message": "SLING-13253 - update-local-site: two problems found reviewing the branch\n\nChecking out the published branch was not preceded by discarding the working\ntree, so it threw CheckoutConflictException whenever the configured checkout was\non another branch with an uncommitted change to a file whose content differs\nbetween that branch and the published one - exactly the case the branch handling\nexists for. The working tree is now reset before switching. The previous test did\nnot catch this because it branched at the same commit, making the switch a no-op;\nthe new one commits a divergent change first.\n\nThe downloads page outcome was decided on counters summed over all of a\nrelease\u0027s artifact ids, so a single already-current entry hid siblings that were\nmissing altogether and the message claimed ids were listed when they were not.\nIt also made the other-major message unreachable whenever anything was current.\nEach artifact id is now classified on its own and every category reported with\nthe ids that actually belong to it.\n\nAlso closes the Git returned by the clone, which leaked the repository and its\npack handles for the rest of the process.\n"
    },
    {
      "commit": "2d5b7e9f89b9aec172d4d545741b5b247cb9eb4b",
      "tree": "4d684a76a7fdce64982307d5e4d2d1246d02e45f",
      "parents": [
        "209fa6967af7465f2b65963dc8de8bbdda10bf87"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 20:51:54 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 21:20:35 2026 +0200"
      },
      "message": "SLING-13253 - update-local-site: fix problems found running the website update\n\nThree problems that only a real run against a real checkout shows.\n\nensureRepo hard-reset whatever branch happened to be checked out. Because the\ncheckout location is configurable it may be a checkout someone else is using,\nwhose branch would then be reset and the release committed onto it, so the\npublished branch is now checked out explicitly first.\n\nCommits set the committer as well as the author: the container has no git\nidentity, so JGit derived one from the process user and hostname, producing\ncommits committed by root@\u003ccontainer id\u003e.\n\nAn entry that already carried the released version was reported as missing from\nthe downloads page, because the result could not distinguish an absent entry\nfrom an up-to-date one. Re-running finalize therefore raised a false alarm; the\ntwo cases are now separate.\n\nAlso silences JGit\u0027s filesystem timestamp resolution warning, which it emits\nwhen it cannot measure the resolution of the directory holding the checkout. It\nlooks like a failure mid-release and there is nothing to act on.\n"
    },
    {
      "commit": "209fa6967af7465f2b65963dc8de8bbdda10bf87",
      "tree": "01fc4f3ed7a8f25b0e06ca6071c535e8782d6f02",
      "parents": [
        "49d8ae70771a785414d72cd5066bd7b89a670ff5",
        "2276fecf19334633ad42d606b5443b5b669a4ee5"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 21:14:48 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 21:14:48 2026 +0200"
      },
      "message": "Merge pull request #41 from apache/issue/SLING-13289\n\nSLING-13289 - Push Sling Committer CLI image to DockerHub"
    },
    {
      "commit": "49d8ae70771a785414d72cd5066bd7b89a670ff5",
      "tree": "f554e7d4f338dab13f8376e8c0c9d493e12aaf48",
      "parents": [
        "9d8b3a368a5c3576d46e77781e2729b7f14da459",
        "819df9cbb9391685fa6adfd60cf3db1bbc91e79c"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Fri Aug 14 18:23:37 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 18:23:37 2026 +0200"
      },
      "message": "Merge pull request #40 from apache/feature/SLING-13253-finalize-site-update\n\nSLING-13253 - finalize: update the Sling website as the last step\n"
    },
    {
      "commit": "819df9cbb9391685fa6adfd60cf3db1bbc91e79c",
      "tree": "f554e7d4f338dab13f8376e8c0c9d493e12aaf48",
      "parents": [
        "a0b8671d3eb6a7a460a94127288fe63224419132"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 08:03:29 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 14 08:03:29 2026 +0200"
      },
      "message": "SLING-13253 - address review feedback on the website update\n\nExtract the dist.apache.org access out of UpdateDistCommand into DistRepository:\npublishing a release and resolving a release\u0027s artifact ids from the published\nPOMs both need it, so it does not belong to any one command, and reaching into a\ncommand for it was a layering smell.\n\nTake the site checkout as a --site-checkout option rather than an environment\nvariable. The env var only existed because the shared helpers resolved it from\nglobal state; the path is now threaded through as a parameter instead, which\nalso removes the system-property juggling the tests needed. Nothing else in the\nCLI takes an option this way - the only other environment variables are the ASF\ncredentials, which are secrets passed through --env-file.\n\nDrive the site command tests against a real repository instead of mocking JGit.\nThe mocks had to be taught about checkout(), setDepth() and setCommitter() one\nbreakage at a time while continuing to pass, which is the wrong way round; these\ntests clone, fetch, commit and push between two local repositories, and one of\nthem immediately caught that the committer identity is not set yet. This matches\nthe rest of the suite, where MockJira and MockNexus are real local HTTP servers\nrather than mocked clients.\n"
    },
    {
      "commit": "2276fecf19334633ad42d606b5443b5b669a4ee5",
      "tree": "0e279949e49d808215aa887b88f868b2b17a7f60",
      "parents": [
        "9b4de6fa9a758ea33e7ba064d6ba36f707f70e3b"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:27:02 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:27:02 2026 +0200"
      },
      "message": "maven invocation cleanup: remove unnneded goals/parameters\n"
    },
    {
      "commit": "9b4de6fa9a758ea33e7ba064d6ba36f707f70e3b",
      "tree": "62e5e93044caa9fc5a8d2087f945ab31c32b18f3",
      "parents": [
        "e07bf7672939f0ee56e8ca8c32d55ea2512d2170"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:23:55 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:23:55 2026 +0200"
      },
      "message": "update maven plugin lifecycle:\n\n- run the build in package phase (more idiomatic Maven IMO)\n- explicitly invoke docker:push in github actions\n  - we don\u0027t want to run deploy in GH actions\n  - install is too early IMO\n- remove docker.skip.push setting, no longer needed\n"
    },
    {
      "commit": "e07bf7672939f0ee56e8ca8c32d55ea2512d2170",
      "tree": "56ceb3cccb398e3c0a08f8dcbbd1890e25bf0cad",
      "parents": [
        "22de43d6fd5bfad450535182343893c72ccde891"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:13:19 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:13:19 2026 +0200"
      },
      "message": "docker push hardening: lock down permissions, add concurrency control\n\nalso allow manually triggering the action\n"
    },
    {
      "commit": "22de43d6fd5bfad450535182343893c72ccde891",
      "tree": "227751ac38368db282f54fae780633cee9a6f23b",
      "parents": [
        "76c0616286e385ca3c2be03c208b07bf1c0a03b6"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:11:35 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:11:35 2026 +0200"
      },
      "message": "switch adopt to temurin\n"
    },
    {
      "commit": "76c0616286e385ca3c2be03c208b07bf1c0a03b6",
      "tree": "6fcac8afca0321c8022d4c6f82011a2fe1597944",
      "parents": [
        "185fa1d116d7acb979773889b9ab7719a9f4b13c"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:05:11 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Aug 11 12:05:11 2026 +0200"
      },
      "message": "Run tests during the docker build + push action\n"
    },
    {
      "commit": "a0b8671d3eb6a7a460a94127288fe63224419132",
      "tree": "7bf4ddf6e20ed8587d4608c7a278a0c97f2390b9",
      "parents": [
        "2fec9b75ee1f2dc53af900a6828eb3e5b3a435d3"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Aug 04 20:23:15 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 07 17:29:26 2026 +0200"
      },
      "message": "SLING-13253 - update-local-site: drop the superseded name-based matching\n\nThe display-name based updateDownloads had no callers left once downloads.tpl\nentries are matched on the artifact id, which also covers the --release path\nbecause the artifact ids are then read from the released POMs in dist/release.\nIts tests are replaced by artifact-id equivalents.\n"
    },
    {
      "commit": "2fec9b75ee1f2dc53af900a6828eb3e5b3a435d3",
      "tree": "554a7dca9cad86ff60836edd5d8e5375f4280d20",
      "parents": [
        "9d8b3a368a5c3576d46e77781e2729b7f14da459"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Aug 04 17:26:43 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 07 17:29:26 2026 +0200"
      },
      "message": "SLING-13253 - finalize: update the Sling website as the last step\n\nPromoting a release also requires updating the website, which finalize did\nnot do. UpdateLocalSiteCommand already edited releases.md and downloads.tpl\nbut only printed a diff, so nothing ever landed.\n\nfinalize now orchestrates that command as step 6/6, reusing its editing and\ncommit/push helpers rather than reimplementing them, following the existing\nplanDistRelease/publishToDistRelease pattern. The checkout is cloned from\ngitbox so the ASF credentials that already commit to dist.apache.org can push.\n\ndownloads.tpl entries are now matched on the artifact id instead of the\ndisplay name. The two routinely differ (Tracer is listed as Log Tracer,\nCommons Mime as Commons Mime Type Service) and one release can own several\nentries (Testing OSGi Mock has .core/.junit4/.junit5), so name matching\nsilently did nothing for roughly a third of releases. Artifact ids come from\nthe staged POMs, or from the released POMs in dist/release when the staging\nrepository has already been dropped, so this works before and after promotion.\n\nOnly entries on the same major version are rewritten. dist/release keeps\nseveral major streams published while the downloads page lists only the\nlatest, so matching on the artifact id alone would have turned a Resource\nResolver 1.12.x maintenance release into a downgrade of the 2.x entry.\n\nThe news page stays a separate, manual command: the release guide only asks\nfor a news entry when a release warrants an announcement.\n"
    },
    {
      "commit": "9d8b3a368a5c3576d46e77781e2729b7f14da459",
      "tree": "157bb080879d5b5d6f26ab393d42d441ffbd0bb3",
      "parents": [
        "0beab24cdc797a03060e9ffea2c7851a04037576",
        "6fdd4b1f96bbabd9cc4391bbbdcf4e1049b7ddc6"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Fri Aug 07 17:28:16 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 07 17:28:16 2026 +0200"
      },
      "message": "Merge pull request #47 from apache/feature/SLING-13253-upgrade-jgit\n\nSLING-13253 - upgrade JGit to 7.7.1\n"
    },
    {
      "commit": "6fdd4b1f96bbabd9cc4391bbbdcf4e1049b7ddc6",
      "tree": "157bb080879d5b5d6f26ab393d42d441ffbd0bb3",
      "parents": [
        "0beab24cdc797a03060e9ffea2c7851a04037576"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 07 17:07:56 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Aug 07 17:14:10 2026 +0200"
      },
      "message": "SLING-13253 - upgrade JGit to 7.7.1\n\nThe 5.13.x line the project tracks is the Java 8 maintenance branch and has no\nshallow clone support, which the website update needs to avoid cloning the\nsite\u0027s full history.\n\nJGit 7 additionally imports org.apache.commons.codec.digest, which Maven had\nmediated down to a version below the range it requires, so commons-codec is\ndeclared explicitly, and javax.management, which the jlink\u0027d JRE did not\ninclude - without that module the bundle silently fails to resolve and the CLI\ndoes nothing at all.\n"
    },
    {
      "commit": "185fa1d116d7acb979773889b9ab7719a9f4b13c",
      "tree": "51d6cc7693210011efe65c1c686a64f71e62de8c",
      "parents": [
        "11622d985a96d673d249d686c5bf852e69271a39"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Thu Aug 06 16:11:51 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Thu Aug 06 16:11:51 2026 +0200"
      },
      "message": "spotless fix\n"
    },
    {
      "commit": "11622d985a96d673d249d686c5bf852e69271a39",
      "tree": "2bf055719a6abe85af48101899c1bd4c99c8a70d",
      "parents": [
        "b620106bce59dec12ec6902daedd814e5f87a2e5",
        "0beab24cdc797a03060e9ffea2c7851a04037576"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Thu Aug 06 16:07:19 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 06 16:07:19 2026 +0200"
      },
      "message": "Merge branch \u0027master\u0027 into issue/SLING-13289"
    },
    {
      "commit": "0beab24cdc797a03060e9ffea2c7851a04037576",
      "tree": "b44e58f1932b9699d8c6350b589edb98f34de4a8",
      "parents": [
        "d2ffd450ff39a01f3dea097b40df1827eb3ff616"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Thu Aug 06 11:04:36 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 06 11:04:36 2026 +0200"
      },
      "message": "fix(deps): update to latest jdk18 version of the BouncyCastle artifacts (#46)\n\nThis fixes several vulnerabilities and also moves away from the jdk15 branch."
    },
    {
      "commit": "d2ffd450ff39a01f3dea097b40df1827eb3ff616",
      "tree": "7c7f14046a13e5d1d4f1e4172548a52c6fd0c6d4",
      "parents": [
        "f5b7f969c85307b70d58929592ee0a4ef2fba76b",
        "88d0f7d9ab7e58920d4e4edb7d2176891c2245c3"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:21:57 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 23:21:57 2026 +0200"
      },
      "message": "Merge pull request #45 from apache/dependabot/maven/org.eclipse.jgit-org.eclipse.jgit-5.13.4.202507202350-r\n\nBump org.eclipse.jgit:org.eclipse.jgit from 5.2.1.201812262042-r to 5.13.4.202507202350-r"
    },
    {
      "commit": "88d0f7d9ab7e58920d4e4edb7d2176891c2245c3",
      "tree": "7d0e4ef7cc89fd0ff402e17a85b839d7bf3115d9",
      "parents": [
        "7cf927c908112dd818792e6df7ed637bc427f780"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:16:20 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:16:20 2026 +0200"
      },
      "message": "chore(deps): also bump org.eclipse.jgit in feature model\n"
    },
    {
      "commit": "f5b7f969c85307b70d58929592ee0a4ef2fba76b",
      "tree": "0e45fda13b38d361ee3167688cee1dc12e14429c",
      "parents": [
        "7703af250fae25906102efa07c8c99b8b87e5430",
        "c1c3d0c4f81ae3b5074ec94e3559e7fb40d0f0ee"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:14:18 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 23:14:18 2026 +0200"
      },
      "message": "Merge pull request #42 from apache/dependabot/maven/ch.qos.logback-logback-classic-1.2.13\n\nBump ch.qos.logback:logback-classic from 1.2.12 to 1.2.13"
    },
    {
      "commit": "7703af250fae25906102efa07c8c99b8b87e5430",
      "tree": "fb6986b5d1875e56990a06a2c3b47172bf698c53",
      "parents": [
        "ace6a4fe5ff635d19d76280f7a0ec506f80f43b1",
        "be3a5c92a9837768fa6672b5559267ec0b67bc78"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:14:03 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 23:14:03 2026 +0200"
      },
      "message": "Merge pull request #44 from apache/dependabot/maven/commons-io-commons-io-2.14.0\n\nBump commons-io:commons-io from 2.7 to 2.14.0"
    },
    {
      "commit": "ace6a4fe5ff635d19d76280f7a0ec506f80f43b1",
      "tree": "03ab371526b69f6bf18e42a062e820d182b6bd00",
      "parents": [
        "42a8704d7454c6d77db2d3b6fce641659488da3a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Aug 05 23:09:15 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 23:09:15 2026 +0200"
      },
      "message": "Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 (#43)\n\nBumps org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0.\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.commons:commons-lang3\n  dependency-version: 3.18.0\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "be3a5c92a9837768fa6672b5559267ec0b67bc78",
      "tree": "4c78ef4b1b080aa11bd2b2f6b886e5359fb1abe8",
      "parents": [
        "08a171add25fc161752166d68e16204bcd973774"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:07:57 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:07:57 2026 +0200"
      },
      "message": "chore(deps): also bump commons-io in the feature model\n"
    },
    {
      "commit": "c1c3d0c4f81ae3b5074ec94e3559e7fb40d0f0ee",
      "tree": "47f313c27148ff723456329635b74525fe6489b0",
      "parents": [
        "6ee8c9ce1130991704c7c1848aebf7c28bc08280"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:07:09 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 23:07:09 2026 +0200"
      },
      "message": "chore(deps): also bump logback in feature model\n"
    },
    {
      "commit": "7cf927c908112dd818792e6df7ed637bc427f780",
      "tree": "d6063569bcb15c69c9c63ebd75a3bb5ebac6a507",
      "parents": [
        "42a8704d7454c6d77db2d3b6fce641659488da3a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Aug 05 16:37:03 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 16:37:03 2026 +0000"
      },
      "message": "Bump org.eclipse.jgit:org.eclipse.jgit\n\nBumps org.eclipse.jgit:org.eclipse.jgit from 5.2.1.201812262042-r to 5.13.4.202507202350-r.\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.jgit:org.eclipse.jgit\n  dependency-version: 5.13.4.202507202350-r\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "08a171add25fc161752166d68e16204bcd973774",
      "tree": "0b4e2e8e28940162ff2082ef7c5c17c92e065bf9",
      "parents": [
        "42a8704d7454c6d77db2d3b6fce641659488da3a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Aug 05 16:36:04 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 16:36:04 2026 +0000"
      },
      "message": "Bump commons-io:commons-io from 2.7 to 2.14.0\n\nBumps commons-io:commons-io from 2.7 to 2.14.0.\n\n---\nupdated-dependencies:\n- dependency-name: commons-io:commons-io\n  dependency-version: 2.14.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "6ee8c9ce1130991704c7c1848aebf7c28bc08280",
      "tree": "f1aeed563a72158a5c40c37e4e1edb44228a320d",
      "parents": [
        "42a8704d7454c6d77db2d3b6fce641659488da3a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Aug 05 16:35:56 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 16:35:56 2026 +0000"
      },
      "message": "Bump ch.qos.logback:logback-classic from 1.2.12 to 1.2.13\n\nBumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) from 1.2.12 to 1.2.13.\n- [Release notes](https://github.com/qos-ch/logback/releases)\n- [Commits](https://github.com/qos-ch/logback/compare/v_1.2.12...v_1.2.13)\n\n---\nupdated-dependencies:\n- dependency-name: ch.qos.logback:logback-classic\n  dependency-version: 1.2.13\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "42a8704d7454c6d77db2d3b6fce641659488da3a",
      "tree": "724be3e96801dc3e4c1506ca8e01a23d96cc9663",
      "parents": [
        "e1481c86a6826bcad88ef3f58e09fdc0ec4bd27a",
        "18d100b3cf356fa816b8441d84ddec618ae3162e"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:08:16 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 18:08:16 2026 +0200"
      },
      "message": "Merge pull request #16 from apache/dependabot/maven/org.bouncycastle-bcprov-jdk15on-1.67\n\nBump bcprov-jdk15on from 1.62 to 1.67"
    },
    {
      "commit": "e1481c86a6826bcad88ef3f58e09fdc0ec4bd27a",
      "tree": "6d6ad08494a00b2a60837f226706ae17fc737e4e",
      "parents": [
        "a63fec226acf1ec275119ee76bdaf44bf8767765",
        "5f1dd3fa573cccd6de0d0dd60fa0374c69ca3065"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:07:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 18:07:59 2026 +0200"
      },
      "message": "Merge pull request #17 from apache/dependabot/maven/com.google.code.gson-gson-2.8.9\n\nBump gson from 2.8.5 to 2.8.9"
    },
    {
      "commit": "a63fec226acf1ec275119ee76bdaf44bf8767765",
      "tree": "23b821f473bd1839a0c3ea6be013f9e8f715536a",
      "parents": [
        "1722e06405800d0aa7060b4ee7c0255257f1fec3",
        "52c08f2095721058c0d7abce960d6c7ce0f8b194"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:07:36 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 18:07:36 2026 +0200"
      },
      "message": "Merge pull request #18 from apache/dependabot/maven/commons-io-commons-io-2.7\n\nBump commons-io from 2.6 to 2.7"
    },
    {
      "commit": "18d100b3cf356fa816b8441d84ddec618ae3162e",
      "tree": "0641a4659a8ecde00717de8f8fef95feacc464c2",
      "parents": [
        "f80deaea44502067c7b461dcb705cfbf5aed2858",
        "1722e06405800d0aa7060b4ee7c0255257f1fec3"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:03:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 18:03:27 2026 +0200"
      },
      "message": "Merge branch \u0027master\u0027 into dependabot/maven/org.bouncycastle-bcprov-jdk15on-1.67"
    },
    {
      "commit": "5f1dd3fa573cccd6de0d0dd60fa0374c69ca3065",
      "tree": "f74263184d0c4d4425fc90592c9946b7865ab261",
      "parents": [
        "934abb59c58a28cafc56b037b363dab10f12d9d4",
        "1722e06405800d0aa7060b4ee7c0255257f1fec3"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:03:04 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 18:03:04 2026 +0200"
      },
      "message": "Merge branch \u0027master\u0027 into dependabot/maven/com.google.code.gson-gson-2.8.9"
    },
    {
      "commit": "52c08f2095721058c0d7abce960d6c7ce0f8b194",
      "tree": "23b821f473bd1839a0c3ea6be013f9e8f715536a",
      "parents": [
        "653309deac5f00eaf3bb1def51fe8e4cb85774c8",
        "1722e06405800d0aa7060b4ee7c0255257f1fec3"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:02:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 18:02:42 2026 +0200"
      },
      "message": "Merge branch \u0027master\u0027 into dependabot/maven/commons-io-commons-io-2.7"
    },
    {
      "commit": "f80deaea44502067c7b461dcb705cfbf5aed2858",
      "tree": "2cbf04ef68f53820bd8377d7ffe87888c56aebe7",
      "parents": [
        "0e523a0116ef8cce361098e77223f218c50a70bb"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:00:49 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 18:00:49 2026 +0200"
      },
      "message": "chore(deps): also bump bcprov-jdk15on in the feature model file\n"
    },
    {
      "commit": "653309deac5f00eaf3bb1def51fe8e4cb85774c8",
      "tree": "15dce27f4ec89f294ff7905a70d88a8ad17f8e71",
      "parents": [
        "5f1539669a83bd10ad6e36342155c2fafade1ec8"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:59:14 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:59:14 2026 +0200"
      },
      "message": "chore(deps): also update commons-io in the feature model\n"
    },
    {
      "commit": "934abb59c58a28cafc56b037b363dab10f12d9d4",
      "tree": "e8d224eaba8996d913e9a2cd2a26b14d9d5fd99f",
      "parents": [
        "88ef42c9bc60b1ee44172d533487d72cf0e278c0"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:58:08 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:58:08 2026 +0200"
      },
      "message": "fix(deps): also update gson in the feature model\n"
    },
    {
      "commit": "b620106bce59dec12ec6902daedd814e5f87a2e5",
      "tree": "7158ff2e6bd0c6255ea41b87b8f5ea8b715a032e",
      "parents": [
        "1722e06405800d0aa7060b4ee7c0255257f1fec3"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:55:41 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:55:41 2026 +0200"
      },
      "message": "SLING-13289 - Push Sling Committer CLI image to DockerHub\n\n- configure GitHub action to push to DockerHub\n- allow multi-arch builds\n- set image to apache/sling-committer-cli as it better reflects its purpose\n  as compared to apache/sling-cli\n- updated documentation\n"
    },
    {
      "commit": "1722e06405800d0aa7060b4ee7c0255257f1fec3",
      "tree": "0ab370419cbfd01e3eae00c793c3e2a3d7101df9",
      "parents": [
        "9b85e224224b7e2eccae2fbdffc53246ed613adb"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:51:12 2026 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 05 17:51:12 2026 +0200"
      },
      "message": "chore(ci): add allowlist-check github action\n\nThis ensures that we don\u0027t accidently introduce actions that are not allowed\n"
    },
    {
      "commit": "9b85e224224b7e2eccae2fbdffc53246ed613adb",
      "tree": "f7ed486760dbdb20b6a279ab5928a06f14c69494",
      "parents": [
        "c3db7c4834d19b07e0b91b4d8a9240724dae8dc6",
        "6ae0e2ddeb1a98ba6f3d38966cbafd474d3a4987"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Aug 04 13:16:16 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Aug 04 13:16:16 2026 +0200"
      },
      "message": "Merge pull request #39 from apache/feature/SLING-13253-update-dist-same-major\n\nSLING-13253 - update-dist: only remove the previous release of the same major version"
    },
    {
      "commit": "6ae0e2ddeb1a98ba6f3d38966cbafd474d3a4987",
      "tree": "f7ed486760dbdb20b6a279ab5928a06f14c69494",
      "parents": [
        "c3db7c4834d19b07e0b91b4d8a9240724dae8dc6"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 03 18:18:57 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 03 18:18:57 2026 +0200"
      },
      "message": "SLING-13253 - update-dist: only remove the previous release of the same major version\n\nAuto-deducing the release to remove from dist/release picked the closest\nolder version regardless of major, so releasing the first version of a new\nmajor line would delete the still-maintained previous line. Restrict the\ncandidates to the major version being released.\n"
    },
    {
      "commit": "c3db7c4834d19b07e0b91b4d8a9240724dae8dc6",
      "tree": "04b5a9d1edfcb53085f006f87e4b27fa8736c236",
      "parents": [
        "7d3a945172c10f311e14e10f6d6d7c2fdc229144",
        "d3725946c54c08025ff63c2434340036d1eba168"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 03 13:35:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 03 13:35:27 2026 +0200"
      },
      "message": "Merge pull request #38 from apache/feature/SLING-13253-tally-votes-finalize-steps\n\nSLING-13253 - tally-votes: list all finalize steps in the result email"
    },
    {
      "commit": "d3725946c54c08025ff63c2434340036d1eba168",
      "tree": "04b5a9d1edfcb53085f006f87e4b27fa8736c236",
      "parents": [
        "7d3a945172c10f311e14e10f6d6d7c2fdc229144"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 03 10:55:12 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Aug 03 10:55:12 2026 +0200"
      },
      "message": "SLING-13253 - tally-votes: list all finalize steps in the result email\n\nThe closing paragraph only mentioned the dist upload and the promotion to\nMaven Central, while finalize also creates the next JIRA version, moves\nunresolved issues, marks the version released and updates the Apache\nReporter System. It also stated the dist-before-Central order twice, once\nin the explanation and again in the ACTION NEEDED line.\n\nBoth the PMC and non-PMC variants now share one FINALIZE_STEPS list that\nmirrors FinalizeCommand, and the ACTION NEEDED line carries only the ask.\n\nReporter data is committee-scoped, so a non-PMC releaser cannot complete\nthat step either - the note now says steps 1 and 5 need PMC membership,\nnot just the dist upload.\n"
    },
    {
      "commit": "7d3a945172c10f311e14e10f6d6d7c2fdc229144",
      "tree": "279ffd3480d598490f5bcd4480657bd0c411fc09",
      "parents": [
        "1ba57e0bd0b7bd5bef8944f9490dad1a6ad7fd85",
        "c31b94608ad23b719e8c45b152a1a46d4f5a4f60"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 29 20:51:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 20:51:38 2026 +0200"
      },
      "message": "Merge pull request #37 from apache/bugfix/finalize-command-description\n\nSLING-13253 - finalize: correct the command help description order"
    },
    {
      "commit": "c31b94608ad23b719e8c45b152a1a46d4f5a4f60",
      "tree": "279ffd3480d598490f5bcd4480657bd0c411fc09",
      "parents": [
        "1ba57e0bd0b7bd5bef8944f9490dad1a6ad7fd85"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 29 20:50:09 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 29 20:50:09 2026 +0200"
      },
      "message": "SLING-13253 - finalize: correct the command help description order\n\nThe one-line @Command description listed \u0027promote to Maven Central\u0027 before\nthe dist.apache.org update, but finalize uploads to dist first (the only\nrepository-dependent step) and then promotes. Reorder the description to\nmatch the actual execution order and the class Javadoc.\n"
    },
    {
      "commit": "1ba57e0bd0b7bd5bef8944f9490dad1a6ad7fd85",
      "tree": "ad7b4ae0b99e92fcbfc7e668f7e6524b356cf657",
      "parents": [
        "aa385862bdc54e3e58b1e724c07bf352017ac4af",
        "c271553b61789a7eeb906fea74f4bf68b55c4832"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 29 07:41:28 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 07:41:28 2026 +0200"
      },
      "message": "Merge pull request #34 from apache/feature/SLING-13253-finalize\n\nSLING-13253 - release finalize command and act-by-name support"
    },
    {
      "commit": "aa385862bdc54e3e58b1e724c07bf352017ac4af",
      "tree": "c33c43ee95396591a4b638e9589a4edeb9f405c4",
      "parents": [
        "0f9c03f79c5b016813ada741b1e6e50d09e7db98",
        "5bfca40163af7dc8a4d90cc56c0fafef0cc211d1"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 29 07:36:11 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 07:36:11 2026 +0200"
      },
      "message": "Merge pull request #32 from apache/feature/SLING-13253-update-dist\n\nSLING-13253 - release update-dist command using embedded SVNKit"
    },
    {
      "commit": "c271553b61789a7eeb906fea74f4bf68b55c4832",
      "tree": "80ed9e3ded8c394c6b805fc5771d2d18f8fff5b7",
      "parents": [
        "cc7ed63e4972d7f009923d932555a105dd750803"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 22:20:06 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 22:20:06 2026 +0200"
      },
      "message": "SLING-13253 - VersionClient: split changelog scan to drop cognitive complexity\n\nlatestFixVersionChange still sat at 16 (limit 15) because of the nested\nitem loop; extract the per-history lookup into fixVersionChangeInstant so\nboth methods stay well under the threshold.\n"
    },
    {
      "commit": "cc7ed63e4972d7f009923d932555a105dd750803",
      "tree": "8dc634269e4507e991efbd1166aeb4ce8b31c7b9",
      "parents": [
        "04a9979e34f89b2f1baf0255ebbf7a6be9bce561"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 22:13:03 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 22:13:03 2026 +0200"
      },
      "message": "SLING-13253 - address SonarCloud code smells on the finalize PR\n\n- Reporter.fetchRegisteredReleaseNames: return an empty set instead of\n  null when the reporter cannot be queried; callers then dedupe against\n  nothing (unchanged behaviour) and the redundant null checks are dropped.\n- FinalizeCommand.call: extract release resolution and step orchestration\n  into helpers to cut cognitive complexity and remove the nested try.\n- VersionClient: extract the changelog scan out of findFixVersionAddedDate\n  (flatter, lower complexity) and replace the duplicated \"issue/\" and\n  \"fixVersions\" literals with constants.\n"
    },
    {
      "commit": "04a9979e34f89b2f1baf0255ebbf7a6be9bce561",
      "tree": "a5af8e9f7da401a058e1b835d1a10b2a56e1300e",
      "parents": [
        "0517850da9b2c4a63d8ca25c73adba50c2cd126b"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 19 21:43:04 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:50 2026 +0200"
      },
      "message": "SLING-13253 - tally-votes: ask a PMC member to finalize when the releaser is not on the PMC\n\nFinalizing a release copies it to the dist directory first and only then\npromotes to Maven Central. Since the dist upload is PMC-only, a non-PMC\nrelease manager cannot drive the finalization in the correct order, so\nthe result email no longer says the releaser will promote the artifacts.\nIt now asks a PMC member to finalize the release (dist first, then\npromote).\n"
    },
    {
      "commit": "0517850da9b2c4a63d8ca25c73adba50c2cd126b",
      "tree": "923d1b9e175f7dc50c333a3be620876feb8be61c",
      "parents": [
        "c1f2399a53bf38fb7a56b54df0dadb87321552fa"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 13 21:03:33 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:50 2026 +0200"
      },
      "message": "SLING-13253 - finalize: remove duplication with the per-step commands; dist removes only the closest older version\n\nAddresses review feedback on PR #34/#32.\n\nDe-duplication: finalize no longer reimplements the dist, reporter and JIRA\nversion steps. Extracted shared units used by both finalize and the standalone\ncommands:\n- Reporter (addrelease.py query + add, with the HTTP-200-on-error body check)\n  used by FinalizeCommand and UpdateReporterCommand.\n- UpdateDistCommand.planDistRelease(...) (download + work out files to publish\n  and remove, incl. the already-published check) used by UpdateDistCommand and\n  FinalizeCommand.\n- JiraVersions.createSuccessorAndMoveUnresolved(...) used by CreateJiraVersionCommand\n  and FinalizeCommand. The JIRA release step already delegates to VersionClient.\n\ndist previous-version handling: listPreviousReleaseFiles now removes only the\nclosest older version (highest version strictly lower than the one published),\nso parallel maintenance streams are left intact (publishing 2.0.4 removes 2.0.2\nbut keeps 1.2.4) and a newer version is never removed.\n\nAlso drop the misleading \"passed command: null\" log in update-reporter.\n"
    },
    {
      "commit": "c1f2399a53bf38fb7a56b54df0dadb87321552fa",
      "tree": "c96a20ad98cb27125ee97173605eb65b16d9fb51",
      "parents": [
        "a926df226033634f69731a193c503537017f0e9a"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 12 22:19:13 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:50 2026 +0200"
      },
      "message": "SLING-13253 - update-reporter: detect addrelease.py failures reported as HTTP 200\n\nSame fix as FinalizeCommand: the standalone update-reporter command only\nchecked the HTTP status, but addrelease.py returns 200 with the error in the\nbody on failure, so failures were reported as success. Inspect the body and\nfail with the reporter\u0027s message when the save did not happen.\n"
    },
    {
      "commit": "a926df226033634f69731a193c503537017f0e9a",
      "tree": "52087ce3da795cad60c3ddab4ae82bbc4e7ab617",
      "parents": [
        "5873f6ca6d758397e4c7a237f5c0c8309b4f0220"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 12 22:09:39 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:50 2026 +0200"
      },
      "message": "SLING-13253 - finalize: detect reporter addrelease.py failures reported as HTTP 200\n\nThe Apache Reporter addrelease.py endpoint returns HTTP 200 even when the save\nfails, with the error in the response body (e.g. \"Could not save. ... have\naccess to this committee data!\"). The reporter step only checked the status\ncode, so it logged success while the release was never recorded — which is why\nJIRA/reporter updates silently did not take effect for a non-PMC user.\n\nInspect the response body: log success only when there is no error marker,\nwarn and continue on the committee-access error (a non-PMC user cannot add\ncommittee release data — a PMC member must), and fail loudly on any other\nerror body.\n"
    },
    {
      "commit": "5873f6ca6d758397e4c7a237f5c0c8309b4f0220",
      "tree": "a974245a75da9025dadb7035f071e7a21dd4a313",
      "parents": [
        "3493afac7bf20d836fd9530a58012507d46b8fd3"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 12 21:17:14 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:50 2026 +0200"
      },
      "message": "SLING-13253 - finalize: guard against late-tagged issues and make finalize resumable\n\nAddresses SLING-13260, where finalize closed an issue that had been tagged\nwith a release\u0027s fix version and resolved only after the artifacts were\nalready staged and voted on, so the fix was never part of that release.\n\n- Detect such issues via the JIRA changelog (when the fix version was added)\n  compared against the Nexus staging-repository creation time, and only\n  consider resolved issues (unresolved ones are moved to the next version).\n- Run this as a read-only pre-flight in FinalizeCommand, before any\n  irreversible action, so the operator can fix the tagging and re-run.\n- Add --force-close-late-issues to override for the legitimate case where the\n  fix version was simply forgotten during the release.\n- Apply the same guard to ReleaseJiraVersionCommand (shared LateFixVersionGuard).\n- Make finalize resumable: reorder so the only repository-dependent step\n  (dist.apache.org) runs before promote (which drops the staging repo);\n  accept --release to resume after promotion; each step now detects whether\n  it is already done and skips it (dist already published, repo promoted,\n  JIRA version released, reporter already lists the release).\n"
    },
    {
      "commit": "3493afac7bf20d836fd9530a58012507d46b8fd3",
      "tree": "bdfa3c3da7b8501e9a51ef176756651a7e416bc3",
      "parents": [
        "ce7f8cbc353269ed4717c2ffcff3425c0b6fab28"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Jul 10 21:08:32 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:50 2026 +0200"
      },
      "message": "SLING-13253 - tally-votes: widen vote-thread lookup window to 6 months\n\nThe 1-month lists.apache.org search window missed vote threads for releases\ntallied more than a month after the vote was called, causing tally-votes to\nreport \"Could not find a corresponding email voting thread\". Widen to 6\nmonths; the release version in the query keeps the match specific.\n"
    },
    {
      "commit": "ce7f8cbc353269ed4717c2ffcff3425c0b6fab28",
      "tree": "83f570b51e51db3c7ff1082fb2af2661c07c15fd",
      "parents": [
        "5bfca40163af7dc8a4d90cc56c0fafef0cc211d1"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 20:49:53 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:50 2026 +0200"
      },
      "message": "SLING-13253 - release finalize command\n\nAdds \u0027release finalize\u0027, which runs all post-vote finalization steps in one\ncommand: promote to Maven Central, publish to dist/release (PMC members only,\nauto-detected), create/release the JIRA version, and report to the Apache\nReporter. Updates the README with the end-to-end release workflow.\n\nPart of splitting PR #28 into per-command changes; builds on the update-dist PR.\n"
    },
    {
      "commit": "5bfca40163af7dc8a4d90cc56c0fafef0cc211d1",
      "tree": "b6ae90f7b5a7f8e046cacee65bb559c27a8c5ad6",
      "parents": [
        "8e1b677eda59718a5b163ceb53075eee2715dc52"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:39 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Mon Jul 20 21:59:39 2026 +0200"
      },
      "message": "SLING-13253 - update-dist: use possessive quantifiers in the version regex\n\nSonarCloud flagged the leading-version pattern (java:S5998): the nested\n\u0027*\u0027 repetition can overflow the stack through backtracking on large\ninputs. Make the quantifiers possessive so the matcher never backtracks;\nthe matched result is unchanged.\n"
    },
    {
      "commit": "8e1b677eda59718a5b163ceb53075eee2715dc52",
      "tree": "c63bb6b349a49ef0efcadcf5e46139e8097b8fbf",
      "parents": [
        "61467642752ff59f649be550d632920382c040de"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 19 21:54:17 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 19 21:54:17 2026 +0200"
      },
      "message": "SLING-13253 - update-dist: exclude .sha512 checksums from the RAT license check\n\nThe .sha512 test fixture added for the source-release sidecar is a bare\nchecksum with no license header, tripping apache-rat. Exclude *.sha512\nalongside the existing *.md5/*.sha1/*.asc exclusions.\n"
    },
    {
      "commit": "61467642752ff59f649be550d632920382c040de",
      "tree": "a67340056581776af97a0fa01bb1dd77fdb1826a",
      "parents": [
        "dcf3f4f911a6b78726ce2618e69c2d3a63de7f14"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 19 21:28:29 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 19 21:28:29 2026 +0200"
      },
      "message": "SLING-13253 - update-dist: download the .sha512 sidecar\n\nThe staged artifacts include a .sha512 checksum for the source-release\narchive, but download() only fetched the .asc/.sha1/.md5 sidecars, so\nthe .sha512 was never published to dist/release. Download it too, and\nskip sidecars the repository does not have (a non-200 response) instead\nof writing the error body to disk as if it were the file, since the\n.sha512 exists only for some artifacts.\n"
    },
    {
      "commit": "dcf3f4f911a6b78726ce2618e69c2d3a63de7f14",
      "tree": "f02b0de33df556b508dac3b215cd82786608af37",
      "parents": [
        "2384282246a1bd1bf080d8bd65c0017ea8f47572"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 19 21:28:19 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sun Jul 19 21:28:19 2026 +0200"
      },
      "message": "SLING-13253 - update-dist: remove only the closest older version\n\nWhen no explicit previous version is given, remove only the highest\nrelease strictly lower than the one being published instead of every\nolder version. This keeps parallel maintenance streams intact\n(publishing 2.0.4 removes 2.0.2 but keeps 1.2.4) and never removes a\nnewer version.\n"
    },
    {
      "commit": "0f9c03f79c5b016813ada741b1e6e50d09e7db98",
      "tree": "1f91dcd29833d3da643d2dd57b54aaea104bcfeb",
      "parents": [
        "698a69f8fd9113d31693e8a5e2eeade1229dc947"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Fri Jul 17 14:41:49 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 14:41:49 2026 +0200"
      },
      "message": "chore(deps): update to docker-maven-plugin v0.48.1 (#36)\n\nThis ensures compatibility with Maven 3.10.0-rc1.\n\nAlso cleaned up the invalid configuration parameter \u0027cleanup\u0027."
    },
    {
      "commit": "2384282246a1bd1bf080d8bd65c0017ea8f47572",
      "tree": "c6b4e7077580fe1e9bb3b6298f95ae19ab36415e",
      "parents": [
        "136a79cc100573ce10aaf1302571a22e6ccd4c0c"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Jul 10 21:12:41 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Fri Jul 10 21:12:41 2026 +0200"
      },
      "message": "SLING-13253 - update-dist: make sun.misc import optional so the bundle resolves\n\nEmbedding lz4-java (used by SVNKit for dist/release commit deltas) added a\nmandatory sun.misc OSGi import, but the jlink JRE in the Docker image does not\nexport that package, so the sling-cli bundle failed to resolve and every\ncommand errored out. Import sun.misc optionally; lz4-java falls back to its\npure-Java path when sun.misc.Unsafe is not wired.\n"
    },
    {
      "commit": "136a79cc100573ce10aaf1302571a22e6ccd4c0c",
      "tree": "7bf21240dd37ed129138a923216b12f7127503b7",
      "parents": [
        "698a69f8fd9113d31693e8a5e2eeade1229dc947"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:44:11 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 21:11:15 2026 +0200"
      },
      "message": "SLING-13253 - release update-dist: publish staged artifacts to dist/release\n\nPublishes a release\u0027s staged artifacts to dist/release/sling on dist.apache.org\nusing the pure-Java SVNKit client over https, and removes the previous release.\n\nFollows the Maven-based Sling release flow: the artifacts are downloaded from\nthe Nexus staging repository and committed to dist/release/sling (Maven releases\nnever stage to dist/dev, which is IDE-tooling-only). SVNKit is embedded into the\nsling-cli bundle via bnd (its OSGi bundles are P2-only, not on Maven Central);\nlz4 is embedded too since SVNKit needs it to generate the commit deltas. The\nsvn+ssh:// stack stays excluded/optional. Integration tests stage a local SVN\nrepository to exercise the real publish/remove operations.\n\nPart of splitting PR #28 into per-command changes; builds on the promote/drop PR.\n"
    },
    {
      "commit": "698a69f8fd9113d31693e8a5e2eeade1229dc947",
      "tree": "4006142f7190da814f9511b5f8332cbee5b499c4",
      "parents": [
        "7fefc1aa23bb0a6da0309d56cf59103a0429a6f1",
        "aa2888f00c6d95f964881ea4a8a620362d6c9724"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Wed Jul 08 21:10:51 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 21:10:51 2026 +0200"
      },
      "message": "Merge pull request #35 from apache/feature/SLING-13253-act-by-name\n\nSLING-13253 - release: act on a release by name"
    },
    {
      "commit": "aa2888f00c6d95f964881ea4a8a620362d6c9724",
      "tree": "4006142f7190da814f9511b5f8332cbee5b499c4",
      "parents": [
        "7fefc1aa23bb0a6da0309d56cf59103a0429a6f1"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 20:49:53 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 21:04:47 2026 +0200"
      },
      "message": "SLING-13253 - release: act on a release by name\n\nLets the post-vote release commands (create-jira-version, release-jira-version,\nupdate-local-site, update-reporter) accept a release by --release name in\naddition to a staging repository id, and adds tests for the JIRA-version and\nverify commands. A CommandProcessor test guards that a multi-word release name\npassed as a quoted argument is parsed intact.\n\nSplit out of the finalize PR (#34) since these changes are independent of the\nfinalize command and can be merged on their own.\n"
    },
    {
      "commit": "7fefc1aa23bb0a6da0309d56cf59103a0429a6f1",
      "tree": "1f128b4aed1e4181ad2bc8f35f8681f75c49e7b6",
      "parents": [
        "b772297c49355bab891f1bdccdb1f91b89034ec4",
        "54790f3c0a1d514c2871ce78128a0a7ba798ef7d"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Wed Jul 08 20:23:50 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 20:23:50 2026 +0200"
      },
      "message": "Merge pull request #33 from apache/feature/SLING-13253-tally-votes\n\nSLING-13253 - release tally-votes: PMC-aware result email"
    },
    {
      "commit": "54790f3c0a1d514c2871ce78128a0a7ba798ef7d",
      "tree": "1f128b4aed1e4181ad2bc8f35f8681f75c49e7b6",
      "parents": [
        "b772297c49355bab891f1bdccdb1f91b89034ec4"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:44:11 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 20:22:39 2026 +0200"
      },
      "message": "SLING-13253 - release tally-votes: PMC-aware result email\n\nMakes \u0027release tally-votes\u0027 aware of PMC membership when counting binding vs\nnon-binding votes and generating the result email.\n\nPart of splitting PR #28 into per-command changes.\n"
    },
    {
      "commit": "b772297c49355bab891f1bdccdb1f91b89034ec4",
      "tree": "4d5cc11ed05dca95d3aab9dae823e3f1932df19f",
      "parents": [
        "6f5d8189cb8b2a5a290d90478f10cd9de0767705",
        "f2e89bc9fbc78d7edf720ae52fffda73111f4b67"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Wed Jul 08 20:21:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 20:21:42 2026 +0200"
      },
      "message": "Merge pull request #31 from apache/feature/SLING-13253-promote-drop\n\nSLING-13253 - release promote and drop staging repository commands"
    },
    {
      "commit": "6f5d8189cb8b2a5a290d90478f10cd9de0767705",
      "tree": "1b1e555941ffde8cb122e62efd1507eaef8d9cf5",
      "parents": [
        "14c3ee77c54376d5d020e632ffafb0838b637465",
        "6799718b39be92b4d98c3f7813f9fffed8f504b0"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Wed Jul 08 20:16:40 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 20:16:40 2026 +0200"
      },
      "message": "Merge pull request #30 from apache/feature/SLING-13253-close-staging\n\nSLING-13253 - release close-staging command"
    },
    {
      "commit": "14c3ee77c54376d5d020e632ffafb0838b637465",
      "tree": "155c8e8e52e8e68ede1ddcaa266f94dd0d58b637",
      "parents": [
        "9e4da69faa9e0ae6908d1f0524204a32a58d3c45",
        "d730858e449c19e9729d7604ec95bbd75bbe1e5b"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "roy@teeuwen.be",
        "time": "Wed Jul 08 20:11:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 20:11:59 2026 +0200"
      },
      "message": "Merge pull request #29 from apache/feature/SLING-13253-list\n\nSLING-13253 - release list: include open Nexus staging repositories"
    },
    {
      "commit": "f2e89bc9fbc78d7edf720ae52fffda73111f4b67",
      "tree": "4d5cc11ed05dca95d3aab9dae823e3f1932df19f",
      "parents": [
        "6799718b39be92b4d98c3f7813f9fffed8f504b0"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:42:54 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:42:54 2026 +0200"
      },
      "message": "SLING-13253 - release promote and drop staging repository commands\n\nAdds \u0027release promote\u0027 and \u0027release drop\u0027, both extending\nAbstractStagingRepositoryCommand to share the execution-mode dispatch.\n\nPart of splitting PR #28 into per-command changes; builds on the close-staging PR.\n"
    },
    {
      "commit": "6799718b39be92b4d98c3f7813f9fffed8f504b0",
      "tree": "1b1e555941ffde8cb122e62efd1507eaef8d9cf5",
      "parents": [
        "d730858e449c19e9729d7604ec95bbd75bbe1e5b"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:42:54 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:42:54 2026 +0200"
      },
      "message": "SLING-13253 - release close-staging command\n\nAdds \u0027release close-staging\u0027 to close an open Nexus staging repository after\n\u0027mvn release:perform\u0027, making it ready for verification and voting.\n\nIntroduces AbstractStagingRepositoryCommand, the shared base for the\nstaging-repository commands (close-staging, promote, drop).\n\nPart of splitting PR #28 into per-command changes; builds on the list PR.\n"
    },
    {
      "commit": "d730858e449c19e9729d7604ec95bbd75bbe1e5b",
      "tree": "155c8e8e52e8e68ede1ddcaa266f94dd0d58b637",
      "parents": [
        "b18e14b36ce68a7e48b96b10ae7589682a3efd38"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:23:17 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Wed Jul 08 08:23:17 2026 +0200"
      },
      "message": "SLING-13253 - address review: extract PomParser, assert bulk actions\n\n- Extract POM parsing and reactor aggregation from RepositoryService into a new\n  PomParser class, tested directly in PomParserTest (no reflection). Addresses\n  the review note that this functionality warrants its own class.\n- MockNexus now records the last staging bulk action, so testPromote/\n  testCloseWithDescription/testDrop assert the command maps to the correct\n  Nexus action (promote/close/delete) instead of verifying nothing.\n"
    },
    {
      "commit": "b18e14b36ce68a7e48b96b10ae7589682a3efd38",
      "tree": "ddb7e98e87a86404c0614ddd4d6301c667f6f6e3",
      "parents": [
        "9e4da69faa9e0ae6908d1f0524204a32a58d3c45"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sat Jul 04 15:02:19 2026 +0200"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Sat Jul 04 15:02:19 2026 +0200"
      },
      "message": "SLING-13253 - release list: include open Nexus staging repositories\n\nExtends \u0027release list\u0027 to also show open Nexus staging repositories and adds\nthe RepositoryService/StagingRepository support the post-vote release commands\nbuild on.\n\nPart of splitting PR #28 into per-command changes.\n"
    },
    {
      "commit": "9e4da69faa9e0ae6908d1f0524204a32a58d3c45",
      "tree": "b6aeac307fc189ed7cf8b82fd4e40ee8e296808e",
      "parents": [
        "9e6c6c35390e2f880d776d3f1f6b88e0434d435d",
        "a32550b528724fde7a830d56f12358d5f7823927"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Mar 11 08:47:16 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 11 08:47:16 2026 +0100"
      },
      "message": "Merge pull request #27 from apache/bugfix/SLING-13134\n\nSLING-13134 - Update Sling Committer CLI to latest parent and compile on Java 24"
    },
    {
      "commit": "a32550b528724fde7a830d56f12358d5f7823927",
      "tree": "b6aeac307fc189ed7cf8b82fd4e40ee8e296808e",
      "parents": [
        "b7614a1ae17300a2a8d22b3dd1d7c179eb06e8dd"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Mar 10 20:28:49 2026 +0100"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Mar 10 20:28:49 2026 +0100"
      },
      "message": "Ignore spotless apply in git blame\n"
    },
    {
      "commit": "b7614a1ae17300a2a8d22b3dd1d7c179eb06e8dd",
      "tree": "06654558e628789a88acff702252d9af0b3bfdc6",
      "parents": [
        "1066ba545e111bd9022ce71ed2655428c168e12f"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Mar 10 20:28:08 2026 +0100"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Mar 10 20:28:08 2026 +0100"
      },
      "message": "Execute spotless:apply\n"
    },
    {
      "commit": "1066ba545e111bd9022ce71ed2655428c168e12f",
      "tree": "6806baa9beb5b2c8012ddb9f77cebb569f56fe94",
      "parents": [
        "9e6c6c35390e2f880d776d3f1f6b88e0434d435d"
      ],
      "author": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Mar 10 20:27:11 2026 +0100"
      },
      "committer": {
        "name": "Roy Teeuwen",
        "email": "royteeuwen@apache.org",
        "time": "Tue Mar 10 20:27:11 2026 +0100"
      },
      "message": "Update to latest parent pom and Java 21\n"
    },
    {
      "commit": "9e6c6c35390e2f880d776d3f1f6b88e0434d435d",
      "tree": "877cc952df5902dfd1682a4f8c9dac7d4fb490c7",
      "parents": [
        "7a83a8d34b1f16e0fbb1248e914a82780ba5dd42"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 06 14:20:02 2025 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Aug 06 14:20:02 2025 +0200"
      },
      "message": "SLING-12866 - Restrict force pushes, auto-delete branches on merge\n"
    },
    {
      "commit": "7a83a8d34b1f16e0fbb1248e914a82780ba5dd42",
      "tree": "770b0c99d198f61e5492effdb4f01225afa6146b",
      "parents": [
        "e7823f86351d1f8ddd42fd89dfdcae7a877c2919",
        "8c7415f8c438e4077f9541d08e8cb6e4b586f438"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Apr 01 17:04:14 2025 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 01 17:04:14 2025 +0200"
      },
      "message": "Merge pull request #22 from apache/issue/SLING-12037\n\nSLING-12037 - Allow overriding the Jira release name"
    },
    {
      "commit": "8c7415f8c438e4077f9541d08e8cb6e4b586f438",
      "tree": "770b0c99d198f61e5492effdb4f01225afa6146b",
      "parents": [
        "bcdaa300f0c0b21e52c338b11f4220700d3b9feb"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Apr 01 16:58:33 2025 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Apr 01 16:58:33 2025 +0200"
      },
      "message": "SLING-12037 - Allow overriding the Jira release name\n"
    },
    {
      "commit": "bcdaa300f0c0b21e52c338b11f4220700d3b9feb",
      "tree": "c532e01b4ce673aa6ddfb3cd00a821717843c875",
      "parents": [
        "e7823f86351d1f8ddd42fd89dfdcae7a877c2919"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Apr 01 16:55:55 2025 +0200"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Tue Apr 01 16:55:55 2025 +0200"
      },
      "message": "SLING-12037 - Allow overriding the Jira release name\n\nExtend arguments parsing to work with single and double quotes.\n"
    },
    {
      "commit": "e7823f86351d1f8ddd42fd89dfdcae7a877c2919",
      "tree": "bdae7e0823225ced07ae15bc4ef757113f35dc64",
      "parents": [
        "6c20c441627296ab4008a3fa2a3804abf4c01f28"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Mon Oct 28 18:10:03 2024 +0100"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Mon Oct 28 18:10:03 2024 +0100"
      },
      "message": "SLING-12459 - Redirect sonarcloud notifications to commits@apache.sling.org\n"
    },
    {
      "commit": "6c20c441627296ab4008a3fa2a3804abf4c01f28",
      "tree": "7e55dbc3c1fd2340478540ae6bac3631007c2048",
      "parents": [
        "cb4348f76e89e4d53db0b8d0ed597e77b22efa63"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Wed Nov 15 16:03:38 2023 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Nov 15 16:03:38 2023 +0100"
      },
      "message": "SLING-12150 - Update to parent pom 52 (#25)\n\n"
    },
    {
      "commit": "cb4348f76e89e4d53db0b8d0ed597e77b22efa63",
      "tree": "c7f82ba9c5e62f8862ec3174a36c9c9ca890fad9",
      "parents": [
        "8bb5533f9f08682364eb8a3e0360d657e2904405"
      ],
      "author": {
        "name": "Dan Klco",
        "email": "klcodanr@users.noreply.github.com",
        "time": "Mon Nov 13 11:05:13 2023 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Nov 13 11:05:13 2023 -0500"
      },
      "message": "SLING-12148 - Fixing CI Validation Failure  (#26)\n\n* Adding more logging to failure to get CI status\r\n\r\n* Catching all exceptions rather than just the expected ones\r\n\r\n* Fixing extra .git suffix\r\n\r\n* Tweaking log message\r\n\r\n* Adding test to verify"
    },
    {
      "commit": "8bb5533f9f08682364eb8a3e0360d657e2904405",
      "tree": "bf949e4eb2c3401f3b6f343753f4e26fc7b242cd",
      "parents": [
        "bd12f44aafd49bef28ca89b627c3220e64cd5f2c"
      ],
      "author": {
        "name": "Robert Munteanu",
        "email": "rombert@apache.org",
        "time": "Fri Nov 10 17:47:47 2023 +0100"
      },
      "committer": {
        "name": "Robert Munteanu",
        "email": "robert.munteanu@gmail.com",
        "time": "Mon Nov 13 15:13:16 2023 +0100"
      },
      "message": "chore: fix javadoc\n"
    }
  ],
  "next": "bd12f44aafd49bef28ca89b627c3220e64cd5f2c"
}
