Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 13 additions & 2 deletions plugins/magpie-release-management/skills/vote-draft/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ argument-hint: "<version>-rcN [--skip-verify-check <reason>]"
capability: capability:resolve
surface_hash: sha256:6d70a52ead840ca2
license: Apache-2.0
measured_tokens: 6661
measured_tokens: 6842
---

<!-- SPDX-License-Identifier: Apache-2.0
Expand Down Expand Up @@ -146,6 +146,11 @@ When `vote_window_hours` is below 72 **and** `--expedited <reason>` is
passed, the skill drafts the `[VOTE]` body with an `[EXPEDITED]`
notice and a one-sentence reason. It also flags the RM's obligation to
note the deviation in the project's next board report per ASF policy.
The `[VOTE]` thread and the planning issue are public, so until the
advisory ships the reason never names a CVE or calls the release a
security fix ([`AGENTS.md` § Confidentiality](../../../../AGENTS.md#confidentiality-of-the-tracker-repository)):
write it neutrally (*"Time-sensitive fix release"*), keep any approval
the RM cited, and tell the RM what was left out.

**Golden rule 5 — verify-rc gate.** The skill refuses to draft the
`[VOTE]` if `release-verify-rc` has not reported PASS on the same RC.
Expand Down Expand Up @@ -374,6 +379,11 @@ planning issue recorded no SWHID or the project declares no
convenience artefacts; only the *Reproducibility record* lines and the
*Convenience artefacts* block vary with what the report provides.

The `[EXPEDITED]` reason is public: until the advisory ships it names no
CVE and does not call the release a security fix (Golden rule 4). Write
it neutrally (*"Time-sensitive fix release"*), keep any approval the RM
cited, and tell the RM what was left out.

Present the draft subject + body to the RM. Ask for confirmation
before proceeding to Step 3. Allow the RM to edit the body before
confirming.
Expand Down Expand Up @@ -452,7 +462,8 @@ Next step: `release-vote-tally` after the window closes.

When the vote is **expedited** (Golden rule 4), use the expedited
variant: mark the header `(expedited)`, note the shortened window,
state the `--expedited` reason, and restate the RM's obligation to
state the `--expedited` reason (the same neutral wording as the `[VOTE]`
body: no CVE, no "security fix" before the advisory), and restate the RM's obligation to
record the deviation in the project's next board report per ASF policy:

```markdown
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,5 +47,12 @@
"type": "regex",
"pattern": "release-approval",
"flags": ""
},
"no_embargoed_security_framing": {
"field": "body",
"type": "regex",
"pattern": "CVE-\\d{4}-\\d+|security fix|vulnerability|vulnerabilities",
"flags": "i",
"negate": true
}
}
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"subject": "[VOTE] Release Apache Airflow 2.10.4 from 2.10.4-rc1",
"body": "To: dev@airflow.apache.org\nSubject: [VOTE] Release Apache Airflow 2.10.4 from 2.10.4-rc1\n\nHi all,\n\nI propose we release the following artifacts as Apache Airflow 2.10.4.\n\nThe release artifacts, signatures, and checksums are available at:\n https://dist.apache.org/repos/dist/dev/airflow/2.10.4-rc1/\n\nThe release tag to be voted upon:\n https://github.com/apache/airflow/releases/tag/2.10.4-rc1\n\nThe changelog for this release:\n https://github.com/apache/airflow/blob/2.10.4-rc1/CHANGELOG.md\n\nKeys to verify artifact signatures:\n https://dist.apache.org/repos/dist/release/airflow/KEYS\n\nHow to verify this candidate before voting\n------------------------------------------\nReproducibility record (from the planning issue):\n repository: https://github.com/apache/airflow\n source commit: a1b2c3d4e5f60718293a4b5c6d7e8f9012345678\n SWHID (content): swh:1:dir:9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c;origin=https://github.com/apache/airflow;anchor=swh:1:rev:a1b2c3d4e5f60718293a4b5c6d7e8f9012345678\n SOURCE_DATE_EPOCH: 1758400000\n sha512: 77ab…10 (apache_airflow-2.10.4.tar.gz)\n\nAgentic path (any agent with the Magpie release skills, read-only):\n /magpie-release-management:verify-rc 2.10.4-rc1\n It checks the signature against KEYS, the checksum, licence headers\n (RAT), LICENSE/NOTICE, prohibited binaries, dangling links, version\n strings, rebuilds the source artefact from the tag to confirm it is\n byte-identical to what is staged and that its SWHID is the recorded\n one, and rebuilds and compares every convenience artefact.\n\nManual path (the same checks, longhand):\n https://github.com/apache/airflow/blob/2.10.4-rc1/docs/verifying-a-release-candidate.md\n Reproducibility background: https://github.com/apache/magpie/blob/main/docs/release-management/reproducibility.md\n\nA binding +1 means you downloaded the artefact, verified it, and built\nand tested it on your own hardware; the tools above are an aid, not a\nsubstitute (https://www.apache.org/legal/release-policy.html#release-approval).\n\nPlease vote to release:\n [ ] +1 Release Apache Airflow 2.10.4\n [ ] +0\n [ ] -1 Do not release (please comment with specific reasons)\n\nThis vote is open for at least 48 hours.\n\n[EXPEDITED: Critical security fix for CVE-2026-12345; abbreviated window approved by PMC chair. ASF policy requires this deviation to be noted in the project's next board report.]\n\nThanks,\n<RM name>",
"body": "To: dev@airflow.apache.org\nSubject: [VOTE] Release Apache Airflow 2.10.4 from 2.10.4-rc1\n\nHi all,\n\nI propose we release the following artifacts as Apache Airflow 2.10.4.\n\nThe release artifacts, signatures, and checksums are available at:\n https://dist.apache.org/repos/dist/dev/airflow/2.10.4-rc1/\n\nThe release tag to be voted upon:\n https://github.com/apache/airflow/releases/tag/2.10.4-rc1\n\nThe changelog for this release:\n https://github.com/apache/airflow/blob/2.10.4-rc1/CHANGELOG.md\n\nKeys to verify artifact signatures:\n https://dist.apache.org/repos/dist/release/airflow/KEYS\n\nHow to verify this candidate before voting\n------------------------------------------\nReproducibility record (from the planning issue):\n repository: https://github.com/apache/airflow\n source commit: a1b2c3d4e5f60718293a4b5c6d7e8f9012345678\n SWHID (content): swh:1:dir:9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c;origin=https://github.com/apache/airflow;anchor=swh:1:rev:a1b2c3d4e5f60718293a4b5c6d7e8f9012345678\n SOURCE_DATE_EPOCH: 1758400000\n sha512: 77ab…10 (apache_airflow-2.10.4.tar.gz)\n\nAgentic path (any agent with the Magpie release skills, read-only):\n /magpie-release-management:verify-rc 2.10.4-rc1\n It checks the signature against KEYS, the checksum, licence headers\n (RAT), LICENSE/NOTICE, prohibited binaries, dangling links, version\n strings, rebuilds the source artefact from the tag to confirm it is\n byte-identical to what is staged and that its SWHID is the recorded\n one, and rebuilds and compares every convenience artefact.\n\nManual path (the same checks, longhand):\n https://github.com/apache/airflow/blob/2.10.4-rc1/docs/verifying-a-release-candidate.md\n Reproducibility background: https://github.com/apache/magpie/blob/main/docs/release-management/reproducibility.md\n\nA binding +1 means you downloaded the artefact, verified it, and built\nand tested it on your own hardware; the tools above are an aid, not a\nsubstitute (https://www.apache.org/legal/release-policy.html#release-approval).\n\nPlease vote to release:\n [ ] +1 Release Apache Airflow 2.10.4\n [ ] +0\n [ ] -1 Do not release (please comment with specific reasons)\n\nThis vote is open for at least 48 hours.\n\n[EXPEDITED: Time-sensitive fix release; abbreviated window approved by PMC chair. ASF policy requires this deviation to be noted in the project's next board report.]\n\nThanks,\n<RM name>",
"vote_window_hours": 48,
"expedited": true,
"skip_verify_logged": false,
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"no_embargoed_security_framing": {
"field": "comment_body",
"type": "regex",
"pattern": "CVE-\\d{4}-\\d+|security fix|vulnerability|vulnerabilities",
"flags": "i",
"negate": true
}
}
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
{
"comment_body": "**Vote open (expedited):** `[VOTE] Release Apache Airflow 2.10.4 from 2.10.4-rc1`\nsent to `dev@airflow.apache.org` on 2026-06-11 10:00 UTC.\nVote window closes: 2026-06-13 10:00 UTC (minimum, 48-hour expedited window).\n\n**Expedited:** Critical security fix for CVE-2026-12345; abbreviated window approved by PMC chair.\nReminder: note this deviation in the project's next board report per ASF policy.\n\nNext step: `release-vote-tally` after the window closes.",
"comment_body": "**Vote open (expedited):** `[VOTE] Release Apache Airflow 2.10.4 from 2.10.4-rc1`\nsent to `dev@airflow.apache.org` on 2026-06-11 10:00 UTC.\nVote window closes: 2026-06-13 10:00 UTC (minimum, 48-hour expedited window).\n\n**Expedited:** Time-sensitive fix release; abbreviated window approved by PMC chair.\nReminder: note this deviation in the project's next board report per ASF policy.\n\nNext step: `release-vote-tally` after the window closes.",
"proposed": true
}