It is essential that you verify the integrity of the downloaded files using the PGP or MD5 signatures.
The PGP signatures can be verified using PGP or GPG. First download the KEYS as well as the PGP signature file for the relevant file. Make sure you get these files from the main distribution directory, rather than from a mirror. Then verify the signatures using, for instance:
% gpg --import KEYS % gpg --verify unomi-1.2.0-incubating.tar.gz.asc unomi-1.2.0-incubating.tar.gz
Here are the release notes for this version of Apache Unomi
Here are the release notes for this version of Apache Unomi