Apache Trusted Releases

Clone this repo:
  1. 164eae4 Derive announcement recipients from the mailing list directory by Sean B. Palmer · 14 hours ago main sbp
  2. 279173f Link vote emails to manifests and retain vote thread URLs by Sean B. Palmer · 15 hours ago
  3. 0d156e9 Update tasks when catalogue releases change by Sean B. Palmer · 18 hours ago production
  4. 3b68f65 Allow empty drafts in validation by Sean B. Palmer · 18 hours ago
  5. 3da0dd9 Add some project key remappings by Sean B. Palmer · 20 hours ago

Apache Trusted Releases (ATR)

A prototype service for verifying and distributing Apache releases securely.

NOTE: New contributors must introduce themselves on the development mailing list first, to deter spam. Contributions are very welcome, but please do not submit a PR until you have introduced yourself.

Status

This repository contains code developed by the Apache Software Foundation (ASF) Tooling team.

As of September 2026, this code is available for ASF feedback. The project is in beta development and we plan to avoid significant changes.

We welcome feedback and discussion, but note that many known issues and design refinements are already scheduled for future iterations. Please review our issue tracker and inline comments before filing new issues.

Beta deployment: https://releases.apache.org/

Note: This repository is now an officially maintained ASF project. It does not represent final technical or policy decisions for future ASF Tooling products. The code is provided without guarantees regarding stability, security, or backward compatibility.

Quick start

Run with Docker Compose (recommended):

git clone https://github.com/apache/tooling-trusted-releases.git
cd tooling-trusted-releases
mkdir -p state
docker compose up --build

Then visit https://127.0.0.1:8080/ (accept the self-signed certificate).

See DEVELOPMENT.md for additional options including running without containers.

Documentation

DocumentDescription
DEVELOPMENT.mdQuick start guide for developers
BUILD.mdBuild instructions and Make targets
CONTRIBUTING.mdHow to contribute code
SUPPORT.mdGetting help and reporting issues
GOVERNANCE.mdProject governance

Online documentation: https://releases.apache.org/docs/

Getting involved

Community feedback is encouraged! If you are an ASF committer or contributor interested in Trusted Releases:

  1. Try it out – The beta test production server allows you to perform the release process.

  2. Introduce yourself on the development mailing list: dev@tooling.apache.org

    Subscribe by sending email with empty subject and body to dev-subscribe@tooling.apache.org and replying to the automated response (per the ASF mailing list how-to).

  3. Share ideas or file issues: Use the GitHub Issues page to report bugs, suggest features, or discuss improvements.

  4. Chat with us: #apache-trusted-releases on ASF Slack

Contributing

See CONTRIBUTING.md for detailed contribution guidelines.

Key resources for contributors:

License

This project is licensed under the Apache License, Version 2.0.


Part of the Apache Tooling Initiative. For more information about the ASF, visit https://www.apache.org/.