We have fixed a few bugs and added enhancements since the release of
Apache Commons Lang 3.20.0, so I would like to release Apache Commons
Lang 3.21.0.

Apache Commons Lang 3.21.0 RC2 is available for review here:
    https://dist.apache.org/repos/dist/dev/commons/lang/3.21.0-RC2
(svn revision 87961)

The Git tag commons-lang-3.21.0-RC2 commit for this RC is
155db038d73fe0ea49612d42ae70f6e48ee3ebb9, which you can browse here:
    
https://gitbox.apache.org/repos/asf?p=commons-lang.git;a=coommons-lang-3.21.0-RC2

Maven artifacts are here:
    
https://repository.apache.org/content/repositories/orgapachecommons-1966/org/apache/commons/commons-lang3/3.21.0/

These are the artifacts and their hashes:

#Release SHA-512s
#Fri Sep 25 20:01:03 UTC 2026
commons-lang3-3.21.0-bin.tar.gz=1c225a75b66946adc007ca774e59671b9c8ac7c0a9f17977829b4530121fadd322ff179a54a9e7d2d4f8bd1095071fe3ee9b8da7902a82351f8b8ce4d530f129
commons-lang3-3.21.0-bin.zip=2297a295c6227a3529f95677e35454ab97a00a259c8fc9593f2d7e0884238ab125c2164c9c19b04783905f5f92f114fb877b3f48f13faa6fe602c70d9bb1a309
commons-lang3-3.21.0-bom.json=2ccf56c8335bb85eb02da9e4197794d6c1dd6e1c18597ecf8fdddd2511b490b7a5479b53042da2bbf07aaf17c426b91f9848e372c25634e81eb000be742a12bc
commons-lang3-3.21.0-bom.xml=ff1bed275935edcf395640ac947dfcc4fe76f2e6e872463e33e0490ac2011dabea68bb2b73020b2373f3c535221cd71c4e77e44e1af8d3979479f102c42ec17e
commons-lang3-3.21.0-javadoc.jar=c425671b84b58a60926f3129fcf93f8f159c98ab2c471cfdb513cf8ad477993ab3c586ca878631011c7ef706811c4c625644c49c16029792f915084d2abe0742
commons-lang3-3.21.0-sources.jar=2c8536097cdbe11df72563752ae2c7860a6b65e51be03db856c7671f255690ddb57bd7c114d97b288067948253d0a2eafceb30a8d5ff95444b864f07ad3f22d7
commons-lang3-3.21.0-src.tar.gz=38b6615e2c9aee7dcc9e259db4edcc003a10b84baea4ae547af9695938a87b8efc91fbb51f194b0fc37e7f18aef47604c17f9fe2ca49df20aeb1d5cc879275e2
commons-lang3-3.21.0-src.zip=21ccdfd23bc9f980c546812e6ec7ec4f65e89abf5f452216e079ea436edbe93371446c1e9886e04776d36965342b7dd0bdb14f6165ad9d71d54ede9f967c997b
commons-lang3-3.21.0-test-sources.jar=911c4c2939072bd1a5b2db980926bf8a555bc8ad3b129b268538ccdba0ca975e73f86369d00c819c39f1d6b343a3317459fe1d7ad7e27ca3ddc4f343399a458b
commons-lang3-3.21.0-tests.jar=6b01be6273901656822da3b231fe1d3faf51adb1ce1a84d07eea67a09f0e014b3f74a03e2986cfd3147c28db7d244e0f2e7c252253a1dda804692ccc036328e5
org.apache.commons_commons-lang3-3.21.0.spdx.json=699833dc0db5a07813f6a57eb1a50acf6abe93b6c5a2d1e5c375d58c0750f4271949c316e44cfc3ad582070f8c90877bcf77c75bf4edd2641cbc2743b56aaf9a


I have tested this with 'mvn' and 'mvn clean install site' using:

openjdk version "25.0.4.1" 2026-08-18
OpenJDK Runtime Environment Homebrew (build 25.0.4.1)
OpenJDK 64-Bit Server VM Homebrew (build 25.0.4.1, mixed mode, sharing)

Apache Maven 3.9.16 (2bdd9fddda4b155ebf8000e807eb73fd829a51d5)
Maven home: /opt/homebrew/Cellar/maven/3.9.16/libexec
Java version: 25.0.4.1, vendor: Homebrew, runtime:
/opt/homebrew/Cellar/openjdk@25/25.0.4.1/libexec/openjdk.jdk/Contents/Home
Default locale: en_US, platform encoding: UTF-8
OS name: "mac os x", version: "26.7", arch: "aarch64", family: "mac"

Darwin ****-MacBook-Pro.local 25.6.0 Darwin Kernel Version 25.6.0: Tue
Aug 18 17:48:46 PDT 2026;
root:xnu-12377.161.15.700.19~2/RELEASE_ARM64_T6041 arm64

Docker version 29.8.0, build 88096ef


Details of changes since 3.20.0 are in the release notes:
    
https://dist.apache.org/repos/dist/dev/commons/lang/3.21.0-RC2/RELEASE-NOTES.txt
    
https://dist.apache.org/repos/dist/dev/commons/lang/3.21.0-RC2/site/changes.html

Site:
    
https://dist.apache.org/repos/dist/dev/commons/lang/3.21.0-RC2/site/index.html
    (Note some *relative* links are broken and the 3.21.0 directories
are not yet created - these will be OK once the site is deployed.)

JApiCmp Report (compared to 3.20.0):
    
https://dist.apache.org/repos/dist/dev/commons/lang/3.21.0-RC2/site/japicmp.html

RAT Report:
    
https://dist.apache.org/repos/dist/dev/commons/lang/3.21.0-RC2/site/rat-report.html

KEYS:
  https://downloads.apache.org/commons/KEYS

Please review the release candidate and vote.
This vote will close no sooner than 72 hours from now.

  [ ] +1 Release these artifacts
  [ ] +0 OK, but...
  [ ] -0 OK, but really should fix...
  [ ] -1 I oppose this release because...

Thank you,

Gary Gregory,
Release Manager (using key 530AA5F25C25011F)

The following is intended as a helper and refresher for reviewers.

Validating a release candidate
==============================

These guidelines are NOT complete.

Requirements: Git, Java, and Maven.

You can validate a release from a release candidate (RC) tag as follows.

1a) Download and decompress the source archive from:

https://dist.apache.org/repos/dist/dev/commons/lang/3.21.0-RC2/source

1b) Check out the RC tag from git (optional)

This is optional,  as a reviewer must at least check source distributions.

git clone https://gitbox.apache.org/repos/asf/commons-lang.git
--branch commons-lang-3.21.0-RC2 commons-lang-3.21.0-RC2
cd commons-lang-3.21.0-RC2

2) Checking the build

All components should include a default Maven goal, such that you can
run 'mvn' from the command line by itself.

2) Check Apache licenses

This step is not required if the site includes a RAT report page,
which you then must check.
This check should be included in the default Maven build, but you can
check it with:

mvn apache-rat:check

3) Check binary compatibility

This step is not required if the site includes a JApiCmp report page,
which you then must check.
This check should be included in the default Maven build, but you can
check it with:

mvn verify -DskipTests -P japicmp japicmp:cmp

4) Build the package

This check should be included in the default Maven build, but you can
check it with:

mvn -V clean package

You can record the Maven and Java version produced by -V in your VOTE reply.
To gather OS information from a command line:
Windows: ver
Linux: uname -a

4b) Check reproducibility

To check that a build is reproducible, run:

mvn clean verify artifact:compare -DskipTests
-Dreference.repo=https://repository.apache.org/content/repositories/staging/
'-Dbuildinfo.ignore=*/*.spdx.json'

Note that this excludes SPDX files from the check.

5) Build the site for a single module project

Note: Some plugins require the components to be installed instead of packaged.

mvn site
Check the site reports in:
- Windows: target\site\index.html
- Linux: target/site/index.html

-the end-

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to