You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Publish the established maka-agent npm package as an ASF-compliant convenience artifact from the exact commit approved as the Apache Maka source release.
Release boundary
The signed source archive is the ASF release artifact and the object of the podling and IPMC votes. The source-RC npm workflow is a credential-free compatibility preflight: it builds and validates the package from the RC commit, but its tarball is not voted on, published, or carried into ASF distribution.
After both source votes approve the candidate, the product Release workflow creates v<version> at that approved commit. npm Stage builds and validates one publication tarball from the final tag, submits those exact bytes through the protected npm-release Environment and OIDC, and leaves public approval to a 2FA-protected maintainer. Finalize verifies the public registry bytes, integrity, signature, provenance, and dist-tag.
This follows Apache OpenDAL's incubating practice while retaining Maka's stronger staged-publishing and post-publication controls. The npm tarball does not need a separate ASF detached PGP signature, ASF SHA-512 sidecar, inclusion in dist/dev or dist/release, or byte identity with a pre-vote preflight build.
Repository implementation status
Repository files and workflows are complete after merged PR #3481. The package already has three maintainers with write access (m4n5ter, astrohan, and kunli666661), with an additional invitation pending for jackwener. The remaining work is external approval/configuration, G3 review, and execution against the real source RC and public package.
Exit criteria
The final product tag, version, and commit identify the IPMC-approved source release; Stage validates and submits one tarball, and Finalize proves the public registry bytes match the Stage record.
The complete production dependency closure rejects Category X, unresolved private workspaces, credentials, local paths, tests, fixtures, and development-only files.
The npm README/version page displays the complete canonical disclaimer from the release commit's DISCLAIMER-WIP; package metadata uses Apache Maka (Incubating) branding and declares Apache-2.0.
Before the first compliant publication, obtain and record explicit mentor or ASF Brand confirmation that maka-agent may be retained; if it is not approved, handle renaming separately without speculative migration machinery.
The source-RC preflight never publishes or moves a dist-tag; npm Stage is possible only after source approval and final product-tag creation.
At least two PPMC npm maintainers hold write access to the unscoped maka-agent package; npm organization ownership is not used as a criterion for an unscoped package.
Trusted Publisher, 2FA recovery, approval and rollback procedures, and the GitHub npm-release Environment can be operated independently by the PPMC.
Clean-install acceptance passes on supported Linux, macOS, and Windows environments using the exact public tarball.
Merged PR refactor(release): align npm preflight with ASF practice #3481 removes the unnecessary candidate handoff/SHA-512/record layer, documents the correct publication boundary and OpenDAL precedent, injects the canonical DISCLAIMER-WIP into the npm README, and adds package branding.
The implementation currently retains maka-agent, but the project must obtain and record explicit mentor or ASF Brand confirmation before the first compliant publication. The Incubator npm guide shows an apache-<project> name, while Apache OpenDAL published the unprefixed opendal package throughout incubation. OpenDAL's package predates its incubation entry whereas maka-agent does not, so the precedent supports requesting the current name but does not settle Maka's naming decision.
Out of scope
Publishing internal @maka/* workspaces as public packages.
Desktop installers and standalone Desktop artifacts.
Treating the npm package as the official ASF source release.
M4n5ter owns delivery and coordination of the complete G8 outcome. This does not replace legal conclusions from G3, publication approval by the PPMC, or authoritative guidance from mentors, the IPMC, ASF Brand, or ASF Legal Affairs.
English
Part of #2974 — G8: npm convenience artifact.
Outcome
Publish the established
maka-agentnpm package as an ASF-compliant convenience artifact from the exact commit approved as the Apache Maka source release.Release boundary
The signed source archive is the ASF release artifact and the object of the podling and IPMC votes. The source-RC npm workflow is a credential-free compatibility preflight: it builds and validates the package from the RC commit, but its tarball is not voted on, published, or carried into ASF distribution.
After both source votes approve the candidate, the product Release workflow creates
v<version>at that approved commit. npm Stage builds and validates one publication tarball from the final tag, submits those exact bytes through the protectednpm-releaseEnvironment and OIDC, and leaves public approval to a 2FA-protected maintainer. Finalize verifies the public registry bytes, integrity, signature, provenance, and dist-tag.This follows Apache OpenDAL's incubating practice while retaining Maka's stronger staged-publishing and post-publication controls. The npm tarball does not need a separate ASF detached PGP signature, ASF SHA-512 sidecar, inclusion in
dist/devordist/release, or byte identity with a pre-vote preflight build.Repository implementation status
Repository files and workflows are complete after merged PR #3481. The package already has three maintainers with write access (
m4n5ter,astrohan, andkunli666661), with an additional invitation pending forjackwener. The remaining work is external approval/configuration, G3 review, and execution against the real source RC and public package.Exit criteria
LICENSE,NOTICE,DISCLAIMER-WIP, README, and required third-party notices reviewed under G3 (legal: audit LICENSE and NOTICE for the first release artifacts #3270).DISCLAIMER-WIP; package metadata usesApache Maka (Incubating)branding and declares Apache-2.0.maka-agentmay be retained; if it is not approved, handle renaming separately without speculative migration machinery.maka-agentpackage; npm organization ownership is not used as a criterion for an unscoped package.npm-releaseEnvironment can be operated independently by the PPMC.Existing work
DISCLAIMER-WIPto CLI tarballs.DISCLAIMER-WIPinto the npm README, and adds package branding.Package-name decision
The implementation currently retains
maka-agent, but the project must obtain and record explicit mentor or ASF Brand confirmation before the first compliant publication. The Incubator npm guide shows anapache-<project>name, while Apache OpenDAL published the unprefixedopendalpackage throughout incubation. OpenDAL's package predates its incubation entry whereasmaka-agentdoes not, so the precedent supports requesting the current name but does not settle Maka's naming decision.Out of scope
@maka/*workspaces as public packages.References
Ownership
M4n5ter owns delivery and coordination of the complete G8 outcome. This does not replace legal conclusions from G3, publication approval by the PPMC, or authoritative guidance from mentors, the IPMC, ASF Brand, or ASF Legal Affairs.
简体中文
#2974 的一部分——G8:npm convenience artifact。
目标结果
从获批为 Apache Maka 源码 release 的精确 commit 发布既有
maka-agent包,使其成为符合 ASF 要求的 npm convenience artifact。发布边界
签名后的源码归档是 ASF release artifact,也是 podling 与 IPMC 的投票对象。source RC 阶段的 npm workflow 是无凭据的兼容性预检:它从 RC commit 构建并验证包,但该 tarball 不参加投票、不公开发布,也不进入 ASF distribution。
两轮源码投票通过后,产品 Release workflow 在同一获批 commit 创建
v<version>。npm Stage 从最终 tag 构建并验证唯一正式发布 tarball,通过受保护的npm-releaseEnvironment 与 OIDC 提交这些精确字节,并由启用 2FA 的 maintainer 人工批准公开。Finalize 校验公共 registry 字节、integrity、signature、provenance 与 dist-tag。这与 Apache OpenDAL 孵化期实践一致,同时保留了 Maka 更严格的 staged publishing 与发布后控制。npm tarball 不需要单独的 ASF PGP detached signature、ASF SHA-512 sidecar、进入
dist/dev或dist/release,也不需要与投票前预检构建保持字节一致。仓库实现状态
PR #3481 合并后,仓库文件与 workflows 已经完成。npm package 已有
m4n5ter、astrohan和kunli666661三位 maintainers 持有 write access,另有jackwener的邀请等待接受。剩余工作是外部认可与配置、G3 审查,以及针对真实 source RC 和公共 package 的发版执行。完成条件
LICENSE、NOTICE、DISCLAIMER-WIP、README 和必需第三方 notices。DISCLAIMER-WIP的完整权威 Incubator disclaimer;package metadata 使用Apache Maka (Incubating)品牌并声明 Apache-2.0。maka-agent的明确认可;如果未获认可,再单独处理改名,不增加假想迁移机制。maka-agentpackage 持有 write access;unscoped package 不以 npm organization ownership 作为关闭条件。npm-releaseEnvironment 可由 PPMC 独立操作。已有工作
DISCLAIMER-WIP。DISCLAIMER-WIP注入 npm README,并补齐 package 品牌。包名决定
当前实现继续使用
maka-agent,但第一次合规发布前必须取得并记录 mentors 或 ASF Brand 的明确认可。Incubator npm 指南给出了apache-<project>名称;Apache OpenDAL 在整个孵化期间发布未加前缀的opendal,但该包早于 OpenDAL 进入孵化器,而maka-agent并非如此。因此这个先例支持请求保留当前名称,不能替 Maka 解决命名判断。不在范围内
@maka/*workspace 作为公共包发布。参考资料
负责人边界
M4n5ter 负责完整 G8 结果的交付与协调。这不会取代 G3 的法律结论、PPMC 的发布批准,以及 mentors、IPMC、ASF Brand 或 ASF Legal Affairs 的权威指导。