Signatures look good, site looks good, reports look good, builds with java 11, 
17, 21, 25.

+1

Thank you Gary!

Cheers,
-Rob

Environment:
% mvn -version          
Apache Maven 3.10.0 (c43a36b8d67be7e0805a411bc0898af1a51f5472)
Maven home: /opt/homebrew/Cellar/maven/3.10.0/libexec
Java version: 25.0.4.1, vendor: Amazon.com Inc., runtime: 
/Library/Java/JavaVirtualMachines/amazon-corretto-25.jdk/Contents/Home
Default locale: en_US, platform encoding: UTF-8, time zone: America/New_York
OS name: "mac os x", version: "27.0", arch: "aarch64", family: "mac"

> On Oct 4, 2026, at 9:10 AM, Gary Gregory <[email protected]> wrote:
> 
> We have fixed a few bugs and added enhancements since the release of
> Apache Commons Codec 1.22.1, so I would like to release Apache Commons
> Codec 1.23.0.
> 
> Apache Commons Codec 1.23.0 RC1 is available for review here:
>    https://dist.apache.org/repos/dist/dev/commons/codec/1.23.0-RC1
> (svn revision 88182)
> 
> The Git tag commons-codec-1.23.0-RC1 commit for this RC is
> 129a2899eecdba9238a9f660a3a534c6d9d6a523, which you can browse here:
>    
> https://gitbox.apache.org/repos/asf?p=commons-codec.git;a=commit;h=129a2899eecdba9238a9f660a3a534c6d9d6a523
> You may checkout this tag using:
>    git clone https://gitbox.apache.org/repos/asf/commons-codec.git
> --branch commons-codec-1.23.0-RC1 commons-codec-1.23.0-RC1
> 
> Maven artifacts are here:
>    
> https://repository.apache.org/content/repositories/orgapachecommons-1968/commons-codec/commons-codec/1.23.0/
> 
> These are the artifacts and their hashes:
> 
> #Release SHA-512s
> #Sun Oct 04 13:04:15 UTC 2026
> commons-codec-1.23.0-bin.tar.gz=34a8cb4bafd3bb56fed56f1609b9c45f8cc25c31d7fdc9fca8df498d9b73efb4b8636b5f8a1c7d6439cca200b35a991867287b4ca14159af8cef4ca56a04559a
> commons-codec-1.23.0-bin.zip=e0b3d7a8bcd0a1ab85d99f53b93f32d3aacdba45eeadafaffd501996fbb0d442b341db65bac214a20d9c46920ca5076d9c436c25e999d520e62d1f84d59f23f9
> commons-codec-1.23.0-bom.json=750c4214cd51f4ed7d341e5bf7f2c0f9e3f0fc7533cb75d32e5f5ffc174abd41a6c81156b466c38454615d2500db8c609bcd87f813669fd74bc8f34be27acd7f
> commons-codec-1.23.0-bom.xml=42de8d6099f59f889d15bcbf4340acf25b5809d1d76642526c4e812f9f48ef8f51ad16513b18be7d1c960de297af6196233fda7b1a582bc82fa81d40991d5aa6
> commons-codec-1.23.0-javadoc.jar=549cc051b9904053c361cc4d77a9e0fd8312ec743baef5f31a7a306797ac72c4c7ea13e2a3f8103943066d827f1f866dfe25dbec75870a746b62eab42fe3aae7
> commons-codec-1.23.0-sources.jar=9c958c30982db35662d3de43a7c666d0f38931e54dc2d55b251515197277f6804b732a3371e86e2e1a90596e35066c1df8b7036d2befc6e2428f280d95a3770b
> commons-codec-1.23.0-src.tar.gz=2196959c34184e85900e09b05911a01f1635fe20489146d3b66a72332fcbd3a1a6393bd6e4f685a8467e2e771b3ea0b3104dae6f9168739f144d394e89d8b5ab
> commons-codec-1.23.0-src.zip=d3c02d59e8426dbeb8ea683b389da641cd490f561a73e6cc422b07aaea0e6ae4b430b2cdc5e5fdecf6bef60f64c43ec071637df878ccca3fbe40066068e355fb
> commons-codec-1.23.0-test-sources.jar=2973afa3a1d6d856b81d313ba5e44acb2ab991e87ea850fbb9099703b134b4c92be6c4649995516726478413218dfcad48b2fac20b4836f8e5e987aad9f22db2
> commons-codec-1.23.0-tests.jar=2afe244aabe967e2dafdfad4ae5f429450c71a0570811a837eccc7892c0fa39e507c1ec19bcf16ed70ec527e83da42903ea879c67b5f2cb2327b1a3b222a1647
> commons-codec_commons-codec-1.23.0.spdx.json=6c5065fb8f5d9c3959a188bc0d4e561cc397888f3952ec0728a04c70517440341c194a0e4517219490e114a441b6003091e13bf95bcd44bd176b037985581c16
> 
> 
> I have tested this with 'mvn' and 'mvn clean install site' using:
> 
> openjdk version "25.0.4.1" 2026-08-18
> OpenJDK Runtime Environment Homebrew (build 25.0.4.1)
> OpenJDK 64-Bit Server VM Homebrew (build 25.0.4.1, mixed mode, sharing)
> 
> Apache Maven 3.10.0 (c43a36b8d67be7e0805a411bc0898af1a51f5472)
> Maven home: /opt/homebrew/Cellar/maven/3.10.0/libexec
> Java version: 25.0.4.1, vendor: Homebrew, runtime:
> /opt/homebrew/Cellar/openjdk@25/25.0.4.1/libexec/openjdk.jdk/Contents/Home
> Default locale: en_US, platform encoding: UTF-8, time zone: UTC
> OS name: "mac os x", version: "26.7.1", arch: "aarch64", family: "mac"
> 
> Darwin Garys-MacBook-Pro.local 25.6.0 Darwin Kernel Version 25.6.0:
> Tue Aug 18 17:48:46 PDT 2026;
> root:xnu-12377.161.15.700.19~2/RELEASE_ARM64_T6041 arm64
> 
> Docker version 29.8.1, build 4a63305
> 
> 
> Details of changes since 1.22.1 are in the release notes:
>    
> https://dist.apache.org/repos/dist/dev/commons/codec/1.23.0-RC1/RELEASE-NOTES.txt
>    
> https://dist.apache.org/repos/dist/dev/commons/codec/1.23.0-RC1/site/changes.html
> 
> Site:
>    
> https://dist.apache.org/repos/dist/dev/commons/codec/1.23.0-RC1/site/index.html
>    (Note some *relative* links are broken and the 1.23.0 directories
> are not yet created - these will be OK once the site is deployed.)
> 
> JApiCmp Report (compared to 1.22.1):
>    
> https://dist.apache.org/repos/dist/dev/commons/codec/1.23.0-RC1/site/japicmp.html
> 
> RAT Report:
>    
> https://dist.apache.org/repos/dist/dev/commons/codec/1.23.0-RC1/site/rat-report.html
> 
> KEYS:
>  https://downloads.apache.org/commons/KEYS
> 
> Please review the release candidate and vote.
> This vote will close no sooner than 72 hours from now.
> 
>  [ ] +1 Release these artifacts
>  [ ] +0 OK, but...
>  [ ] -0 OK, but really should fix...
>  [ ] -1 I oppose this release because...
> 
> Thank you,
> 
> Gary Gregory,
> Release Manager (using key 530AA5F25C25011F)
> 
> The following is intended as a helper and refresher for reviewers.
> 
> Validating a release candidate
> ==============================
> 
> These guidelines are NOT complete.
> 
> Requirements: Git, Java, and Maven.
> 
> You can validate a release from a release candidate (RC) tag as follows.
> 
> 1a) Download and decompress the source archive from:
> 
> https://dist.apache.org/repos/dist/dev/commons/codec/1.23.0-RC1/source
> 
> 1b) Check out the RC tag from git (optional)
> 
> This is optional,  as a reviewer must at least check source distributions.
> 
> git clone https://gitbox.apache.org/repos/asf/commons-codec.git
> --branch commons-codec-1.23.0-RC1 commons-codec-1.23.0-RC1
> cd commons-codec-1.23.0-RC1
> 
> 2) Checking the build
> 
> All components should include a default Maven goal, such that you can
> run 'mvn' from the command line by itself.
> 
> 2) Check Apache licenses
> 
> This step is not required if the site includes a RAT report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
> 
> mvn apache-rat:check
> 
> 3) Check binary compatibility
> 
> This step is not required if the site includes a JApiCmp report page,
> which you then must check.
> This check should be included in the default Maven build, but you can
> check it with:
> 
> mvn verify -DskipTests -P japicmp japicmp:cmp
> 
> 4) Build the package
> 
> This check should be included in the default Maven build, but you can
> check it with:
> 
> mvn -V clean package
> 
> You can record the Maven and Java version produced by -V in your VOTE reply.
> To gather OS information from a command line:
> Windows: ver
> Linux: uname -a
> 
> 4b) Check reproducibility
> 
> To check that a build is reproducible, run:
> 
> mvn clean verify artifact:compare -DskipTests
> -Dreference.repo=https://repository.apache.org/content/repositories/staging/
> '-Dbuildinfo.ignore=*/*.spdx.json'
> 
> Note that this excludes SPDX files from the check.
> 
> 5) Build the site for a single module project
> 
> Note: Some plugins require the components to be installed instead of packaged.
> 
> mvn site
> Check the site reports in:
> - Windows: target\site\index.html
> - Linux: target/site/index.html
> 
> -the end-
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
> 


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to