[Release] Add support for verifying .{asc,sha256,512} for .jar related files in `dev/release/verify_rc.sh`

Open
#593 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
35/100
Issue type
Feature
Clarity
Clearly specified
Activity status
Stale
Tech stack
github, java, shell
Domain
release, security

Research direction

Start with dev/release/verify_rc.sh and inspect how binary artifacts are downloaded and named from GitHub Releases. Add coverage for .asc, .sha256, and .sha512 files associated with .jar artifacts, using the verification commands in the issue; done means signatures and both checksum formats are checked.

Written by the indexing model from the issue text.

Description

Type: enhancement
Describe the enhancement requested

We should:

  • Download binary artifacts from GitHub Release
  • Verify signature by gpg --verify XXX.asc XXX
  • Verify checksum by sha256 -c XXX.sha256 and sha512 -c XXX.sha512
Dominant language
Java
Stars
95
Forks
154
Avg merge
2d 10h
Merged PRs (30d)
11

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/arrow-java

All issues in apache/arrow-java

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.