Skip to content

[TRACKING] First Apache Maka (Incubating) release #2974

Description

@Astro-Han
English

Goal

Track the gates for the first Apache Maka (Incubating) release. Sub-issues own implementation; this issue records gate status and exit conditions only.

Scope of the first release

Two deliverables ship together, on separate tracks.

The ASF release is the Incubator source release: apache-maka-<version>-incubating-src.tar.gz, carrying DISCLAIMER-WIP while its disclosed items stay open. It is what the podling and IPMC vote on.

Product availability means users can install Maka: the maka-agent npm package and the macOS/Windows Desktop artifacts. Under ASF policy these are convenience artifacts rather than part of the release, and they must be built from the approved source release at the same version and commit. That is a policy classification, not a reason to defer them — both are required for the first release.

The two tracks gate differently. Source approval is blocked by G1, G3, G4, G5, and G7. Product availability is blocked by G8 and G9. Desktop additionally cannot ship until bundled Git via Dugite (GPLv2, Category X) is removed and the ASF signing identities are provisioned; DISCLAIMER-WIP cannot waive the former, and project-owned credentials cannot substitute for ASF signing authority. These independent prerequisites are tracked in #3411 and #3414.

Status

Gate Status Exit condition Execution issue
G1: Incoming IP and provenance Blocked Human contributor review, contributor confirmations, SGA/ICLA coverage, and the required mentor/ASF determination are complete #3268; audit PR #2907; #3293
G2: Source release mechanics Complete Reproducible source archive, SHA-512, signing/KEYS path, clean-archive build and tests, dist/dev runbook, and vote templates work #3269; PR #3278; hotfix #3332
G3: Release legal files Blocked The source artifact has audited LICENSE/NOTICE contents and no Category X material #3270; PR #3325
G4: Source headers and RAT In progress The agreed ASF header policy is applied and an automated release audit passes against the extracted archive #3271
G5: Incubator branding In progress Repository, README, and website/download surfaces identify Apache Maka as incubating and distinguish source from convenience artifacts #3272; #3404; PR #3391; PR #3262
G6: Export classification Not applicable Mentor guidance is that the ASF cryptography notification process does not apply #3273 (closed)
G7: Existing distribution remediation Inventory can start now; disposition needs mentors Post-incubation GitHub/npm releases and the bundled-Git binary path are labeled, remediated, or otherwise resolved #3274
G8: npm convenience artifact Repository implementation complete; external configuration and release execution pending Published from the approved source-release commit after approval; canonical disclaimer, explicit mentor/ASF Brand package-name confirmation, G3 review, independently operable PPMC trusted-publishing/2FA controls, registry provenance, and platform acceptance pass #3275; merged PRs #3222/#3335/#3481; three npm maintainers have write access
G9: Desktop convenience artifacts Blocked on bundled Git (#3411) and ASF signing identities (#3414) No Category X content; ASF Apple Developer Program and eSigner access provisioned; artifact-specific legal files/signatures/hashes and platform acceptance complete #3276; #3411; #3414; #3222

Create the release execution issue for a specific <version>-incubating-rc<rc> once G1, G3, G4, G5, and G7 are release-ready. npm and Desktop publication follows source approval and is tracked in the same execution issue.

Foundation already in place: incubation on 2026-08-13, repository at apache/maka, podling status page and mailing lists, root LICENSE/NOTICE/DISCLAIMER-WIP (#3141), and DISCLAIMER-WIP in CLI packages (#3220). None of that implies release approval.

Tracking rules

  1. One sub-issue per independently reviewable outcome. Reuse an existing issue only when its exit condition is identical.
  2. Every pull request on the release path links its sub-issue and states which exit condition it satisfies.
  3. A related PR does not make its author responsible for a wider legal, governance, or release scope. An unassigned blocker is still a blocker.
  4. Once a candidate enters a vote its bytes are immutable; any change needs a new RC number and a fresh vote.

References

简体中文

目标

追踪第一次 Apache Maka(孵化中)发版的各项门槛。Sub-issues 负责实现细节;本 issue 只记录 gate 状态与退出条件。

第一次发版的范围

两项交付一起发布,但走两条不同的轨道。

ASF release 是 Incubator 源码 release:apache-maka-<version>-incubating-src.tar.gz,在披露事项仍然开放期间保留 DISCLAIMER-WIP。它是 podling 和 IPMC 投票的对象。

产品可用性指用户装得上 Maka:maka-agent npm 包和 macOS/Windows Desktop artifacts。在 ASF 政策下它们是 convenience artifacts 而不是 release 的组成部分,必须由获批源码 release 以相同版本和 commit 构建。这只是政策上的归类,不是推迟它们的理由——两者都是第一次发版的必需交付。

两条轨道的阻塞项不同。源码获批被 G1、G3、G4、G5、G7 阻塞;产品可用性被 G8、G9 阻塞。Desktop 还必须先移除通过 Dugite 捆绑的 Git(GPLv2,Category X),并取得 ASF 的平台签名身份;DISCLAIMER-WIP 不能豁免前者,项目自有凭据也不能替代 ASF 签名 authority。这两个相互独立的前置项分别由 #3411#3414 追踪。

当前状态

Gate 状态 退出条件 执行 issue
G1:代码来源与知识产权输入 阻塞 完成人工贡献负责人审查、贡献者确认、SGA/ICLA 覆盖,以及所需的 mentor/ASF 判断 #3268;审计 PR #2907#3293
G2:源码发版机制 已完成 可重复源码归档、SHA-512、签名/KEYS 路径、干净归档构建与测试、dist/dev runbook 和投票模板可用 #3269;PR #3278;hotfix #3332
G3:发行包法律文件 阻塞 源码 artifact 具备经过审计的 LICENSE/NOTICE,且无 Category X 材料 #3270;PR #3325
G4:源码 headers 与 RAT 进行中 落实约定的 ASF header 策略,自动化发版审计对解压后的归档通过 #3271
G5:孵化器品牌 进行中 仓库、README 和网站/下载界面一致标识 Apache Maka 正在孵化,并区分源码与 convenience artifacts #3272#3404;PR #3391;PR #3262
G6:出口分类 不适用 依 mentor 指导,ASF 密码学通知流程不适用 #3273(已关闭)
G7:已有分发补救 盘点可立即开始;处置需 mentors 决定 按指导标注、补救或以其他方式解决进入孵化器后的 GitHub/npm 版本及 bundled Git 二进制路径 #3274
G8:npm convenience artifact 仓库实现已完成;外部配置与真实发版执行待完成 源码获批后从同一 commit 发布;权威免责声明、mentors/ASF Brand 对包名的明确认可、G3 审查、PPMC 可独立操作的 trusted-publishing/2FA 控制、registry provenance 与平台验收通过 #3275;已合并 PR #3222/#3335/#3481;已有三位 npm maintainers 持有 write access
G9:Desktop convenience artifacts 阻塞于 bundled Git(#3411)和 ASF 签名身份(#3414 不含 Category X;取得 ASF Apple Developer Program 与 eSigner 权限;完成针对 artifact 的法律文件、签名/hash 和平台验收 #3276#3411#3414#3222

当 G1、G3、G4、G5、G7 具备发版条件后,为具体的 <version>-incubating-rc<rc> 创建发版执行 issue。npm 和 Desktop 的发布在源码获批之后进行,并在同一个执行 issue 中跟踪。

已完成的基础工作:2026-08-13 进入孵化器、仓库迁移到 apache/maka、podling 状态页与邮件列表、根目录 LICENSE/NOTICE/DISCLAIMER-WIP#3141),以及 CLI 包携带 DISCLAIMER-WIP#3220)。这些都不等于 release 获得批准。

追踪规则

  1. 每个可独立审查的结果保留一个 sub-issue;只有退出条件完全相同时才复用现有 issue。
  2. 发版路径上的每个 PR 必须关联其推进的 sub-issue,并说明满足了哪个退出条件。
  3. 相关 PR 不会让其作者承担更宽的法律、治理或发版范围。Unassigned blocker 仍然是 blocker。
  4. 候选进入投票后其字节不可变;任何变化都需要新的 RC 序号和重新投票。

参考资料


The 2026-08-21 revision separates the ASF release track from the product-availability track and was prepared with Claude Code; it must be reviewed by a human contributor of record. Release, licensing, and provenance conclusions remain with the PPMC, mentors, IPMC, and ASF Legal Affairs as applicable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions