Re: SHA512 by default for GPG sigs

2016-05-18 Thread Sergio Fernández
+1 On Wed, May 18, 2016 at 7:45 PM, Christopher wrote: > Hi all, > > I'm not sure a better list to get feedback on, but I wanted to bring > attention to the proposal here: > https://issues.apache.org/jira/browse/MPOM-118 > > Essentially this is a suggestion to configure the maven-gpg-plugin to s

Re: SHA512 by default for GPG sigs

2016-05-18 Thread Stian Soiland-Reyes
In principle +1, a PGP signature based on sha1 is not cryptographically strong. Obviously blindly checking a PGP signature, even after importing the KEYS from https://www.apache.org/dist, that is also not any proof you got the intended release, just an artifact by someone who previously signed som

Re: slides for ApacheCon NA 2016?

2016-05-18 Thread Sergio Fernández
On Wed, May 18, 2016 at 7:05 PM, Rich Bowen wrote: > Session Slides: > Session slides can be found within the schedule. To view slides, click > here - > > http://events.linuxfoundation.org/events/apache-big-data-north-america/program/schedule > - choose the session you’d like slides for and a pdf

Re: ApacheCon audio processing: Instructions

2016-05-18 Thread Hadrian Zbarcea
Hi Rich, Please find the Thu talks here [1]. Please mark them as done in the spreadsheet so we cleanup the space on drive and start processing another day. Thanks, Hadrian [1] https://drive.google.com/folderview?id=0B4KM_amLomv0MzBEZUZhRzdYTDQ On 05/17/2016 04:39 PM, Rich Bowen wrote: Exc

Re: SHA512 by default for GPG sigs

2016-05-18 Thread Christopher
Yes, that is correct. I'm referring to the ASF-wide parent pom. If I understand the situation correctly, releases of that POM are managed by the Maven PMC, but because of it's utility throughout the ASF, Hervé Boutemy had commented on MPOM-118 that it should be brought to the attention of a larger

Re: How do you measure the effectiveness of mentorship at the Apache Software Foundation?

2016-05-18 Thread Daniel Ruggeri
Hi, Will; This is a great place to ask that question, but another great place would be gene...@incubator.apache.org. -- Daniel Ruggeri Original Message From: William Larkin Sent: May 18, 2016 1:23:03 PM CDT To: dev@community.apache.org Subject: How do you measure the effec

Re: SHA512 by default for GPG sigs

2016-05-18 Thread Greg Trasuk
Whoops. Sorry about that. Greg > On May 18, 2016, at 2:50 PM, Benson Margulies wrote: > > Greg, the proposal is for the _Default ASF POM_ to be set up so that > _all_ projects would use SHA-512. This is not a question for the Maven > PMC. > > On Wed, May 18, 2016 at 1:58 PM, Greg Trasuk wrot

How do you measure the effectiveness of mentorship at the Apache Software Foundation?

2016-05-18 Thread William Larkin
Hello, My name is Will Larkin, and I am working with at team to develop software for mentoring programs to better measure effectiveness and outcomes. We would love to gain some of your insights into how you currently measure effectiveness and other aspects of your mentorship program. 1) How do yo

Re: SHA512 by default for GPG sigs

2016-05-18 Thread Andy Seaborne
On 18/05/16 18:58, Greg Trasuk wrote: Hi Christopher: Thanks for your involvement. Apache Maven is one of many projects at the Apache Software Foundation. Each project has its own mailing lists. So your discussion should probably go to d...@maven.apache.org, which I’ve cc’d on this respon

Re: SHA512 by default for GPG sigs

2016-05-18 Thread Benson Margulies
Greg, the proposal is for the _Default ASF POM_ to be set up so that _all_ projects would use SHA-512. This is not a question for the Maven PMC. On Wed, May 18, 2016 at 1:58 PM, Greg Trasuk wrote: > > Hi Christopher: > > Thanks for your involvement. Apache Maven is one of many projects at the >

Re: SHA512 by default for GPG sigs

2016-05-18 Thread Greg Trasuk
Hi Christopher: Thanks for your involvement. Apache Maven is one of many projects at the Apache Software Foundation. Each project has its own mailing lists. So your discussion should probably go to d...@maven.apache.org, which I’ve cc’d on this response. If you’re not subscribed to that li

SHA512 by default for GPG sigs

2016-05-18 Thread Christopher
Hi all, I'm not sure a better list to get feedback on, but I wanted to bring attention to the proposal here: https://issues.apache.org/jira/browse/MPOM-118 Essentially this is a suggestion to configure the maven-gpg-plugin to sign using SHA512 as its digest algorithm in the ASF Parent POM, used b

Re: slides for ApacheCon NA 2016?

2016-05-18 Thread Rich Bowen
Session Slides: Session slides can be found within the schedule. To view slides, click here - http://events.linuxfoundation.org/events/apache-big-data-north-america/program/schedule - choose the session you’d like slides for and a pdf will be attached in the session description field if the speaker

Re: slides for ApacheCon NA 2016?

2016-05-18 Thread Sergio Fernández
Rich, any news about this? Thanks. On Sat, May 14, 2016 at 7:22 PM, Rich Bowen wrote: > I'll get you an answer for sure Monday. I have the info somewhere but I'm > still traveling > On May 13, 2016 00:36, "Sergio Fernández" wrote: > > > LF has changed the proposals system. But the new one also