Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 598471 - Review Request: maven-gpg-plugin - sign all of the project's attached artifacts with GnuPG.
Summary: Review Request: maven-gpg-plugin - sign all of the project's attached artifac...
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Alexander Kurtakov
QA Contact: Fedora Extras Quality Assurance
Depends On:
TreeView+ depends on / blocked
Reported: 2010-06-01 13:07 UTC by Stanislav Ochotnicky
Modified: 2010-06-04 07:20 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2010-06-04 07:20:27 UTC
akurtako: fedora-review+
kevin: fedora-cvs+

Attachments (Terms of Use)

Description Stanislav Ochotnicky 2010-06-01 13:07:31 UTC
Spec URL:

This plugin signs all of the project's attached artifacts with GnuPG. It adds goals gpg:sign and gpg:sign-and-deploy-file.

Note that this package has dependencies available only in dist-f14-maven221 target. Koji build:

Comment 1 Alexander Kurtakov 2010-06-01 20:06:17 UTC

OK: rpmlint must be run on every package. Output:
aven-gpg-plugin.noarch: W: no-documentation
maven-gpg-plugin.noarch: W: non-conffile-in-etc /etc/maven/fragments/maven-gpg-plugin

False positives. 

OK: The package must be named according to the Package Naming Guidelines .
OK: The spec file name must match the base package %{name}, in the format
%{name}.spec unless your package has an exemption. 
OK: The package must meet the Packaging Guidelines .
OK: The package must be licensed with a Fedora approved license and meet the
Licensing Guidelines .
OK: The License field in the package spec file must match the actual license.
OK: If (and only if) the source package includes the text of the license(s) in
its own file, then that file, containing the text of the license(s) for the
package must be included in %doc.
OK: The spec file must be written in American English. 
OK: The spec file for the package MUST be legible. 
OK: The sources used to build the package must match the upstream source, as
provided in the spec URL. 
OK: The package MUST successfully compile and build into binary rpms on at
least one primary architecture. 
OK: All build dependencies must be listed in BuildRequires, except for any that
are listed in the exceptions section of the Packaging Guidelines ; inclusion of
those as BuildRequires is optional. Apply common sense.
OK: Packages must NOT bundle copies of system libraries.
OK: A package must own all directories that it creates. If it does not create a
directory that it uses, then it should require a package which does create that
OK: A Fedora package must not list a file more than once in the spec file's
%files listings. 
OK: Permissions on files must be set properly. Executables should be set
with executable permissions, for example. Every %files section must include a
%defattr(...) line. 
OK: Each package must consistently use macros. 
OK: The package must contain code, or permissable content. 
OK: Large documentation files must go in a -doc subpackage. 
OK: If a package includes something as %doc, it must not affect the runtime of
the application. 
OK: Packages must not own files or directories already owned by other packages. 
OK: All filenames in rpm packages must be valid UTF-8.    
OK: Provides/Obsoletes are good.

FIXIT: Package is missing Requires: gnupg2 . I know it's not obvious but at runtime this package execs gpg. See line 143

Comment 2 huwang 2010-06-02 01:46:13 UTC
I noticed add_to_maven_depmap maven-antrun-plugin, it should be maven-gpg-plugin.

Comment 3 Alexander Kurtakov 2010-06-02 06:40:24 UTC
Thanks huwang.
Stanislav: please fix before importing

Comment 4 Alexander Kurtakov 2010-06-02 06:41:27 UTC
Ideally it should become %{name}

Comment 5 Stanislav Ochotnicky 2010-06-02 07:46:16 UTC
Thanks huwang for noticing, it's really better to have more pairs of eyes...

I was also wondering about gnupg2 dependency, but it wasn't mentioned on the plugin web page so I thought that maybe they used some pure java implementation...Should have checked...

Anyway, those things are fixed:

Spec URL:

Koji build:

Comment 6 Alexander Kurtakov 2010-06-02 07:59:31 UTC
This package is APPROVED.

Comment 7 Stanislav Ochotnicky 2010-06-02 08:34:19 UTC
Thanks for the review. Requesting CVS:

New Package CVS Request
Package Name: maven-gpg-plugin
Short Description: Plugin to sign all of the project's attached artifacts with GnuPG.
Owners: sochotni 

Comment 8 Kevin Fenzi 2010-06-03 20:34:20 UTC
CVS done (by

Comment 9 Stanislav Ochotnicky 2010-06-04 07:20:27 UTC
Package built:


Note You need to log in before you can comment on or make changes to this bug.