From 8e596fe6a904ab191ef7980a8d545982749e3622 Mon Sep 17 00:00:00 2001 From: ian zhang Date: Fri, 11 Sep 2026 11:44:56 +0800 Subject: [PATCH] build: set fixed project.build.outputTimestamp for reproducible builds Set a fixed ISO-8601 outputTimestamp in pom.xml so every build produces identical artifacts, as required for reproducible builds. Also document this step in the community release guide (EN + zh-cn) with a reference to the Maven reproducible-builds guide. --- pom.xml | 10 +++++----- website/community/release/release-version.md | 10 ++++++++++ .../current/release/release-version.md | 10 ++++++++++ 3 files changed, 25 insertions(+), 5 deletions(-) diff --git a/pom.xml b/pom.xml index 6de8cd0bd..c02efd4b3 100644 --- a/pom.xml +++ b/pom.xml @@ -81,11 +81,11 @@ under the License. 2.1.0-incubating UTF-8 - - + + 2026-09-10T00:00:00Z 1.8 1.8 1.8 diff --git a/website/community/release/release-version.md b/website/community/release/release-version.md index 168ae091c..1cf5e12cf 100644 --- a/website/community/release/release-version.md +++ b/website/community/release/release-version.md @@ -316,6 +316,7 @@ For example, to release version `2.0.0-incubating`, follow these steps: - Create a new branch `2.0.0-incubating` as the release branch. - Update the version number in `pom.xml` to `2.0.0-incubating`. +- Set the `project.build.outputTimestamp` in `pom.xml` to a fixed ISO-8601 timestamp (e.g., the release branch creation time) to ensure [reproducible builds](https://maven.org.cn/guides/mini/guide-reproducible-builds.html). If it is left empty, every build records a different timestamp, which does not satisfy reproducible-build requirements. - Push the RC (Release Candidate) version tag. ```bash @@ -329,6 +330,15 @@ git tag -s 2.0.0-incubating-rc1 -m "release: release for 2.0.0-incubating RC1" git push origin 2.0.0-incubating-rc1 ``` +When the version is updated, also set a fixed build timestamp: + +```bash +# Set a fixed build timestamp so every build produces identical artifacts +mvn versions:set-property -Dproperty=project.build.outputTimestamp -DnewVersion=2026-09-10T00:00:00Z +# Or edit pom.xml directly: +# 2026-09-10T00:00:00Z +``` + #### 3.3.2 Push Binary Packages Compile the source code of the pre-release RC branch and push the binary packages to the [staging repository](https://repository.apache.org/#stagingRepositories). diff --git a/website/i18n/zh-cn/docusaurus-plugin-content-docs-community/current/release/release-version.md b/website/i18n/zh-cn/docusaurus-plugin-content-docs-community/current/release/release-version.md index b22470a52..5fd68990a 100644 --- a/website/i18n/zh-cn/docusaurus-plugin-content-docs-community/current/release/release-version.md +++ b/website/i18n/zh-cn/docusaurus-plugin-content-docs-community/current/release/release-version.md @@ -316,6 +316,7 @@ svn ci -m "add gpg key for xxx" - 创建一个新分支`2.0.0-incubating`作为发布分支 - 修改 `pom.xml` 中的版本号为 `2.0.0-incubating` +- 将 `pom.xml` 中的 `project.build.outputTimestamp` 设置为固定的 ISO-8601 时间戳(例如发布分支的创建时间),以保证[可复现构建](https://maven.org.cn/guides/mini/guide-reproducible-builds.html)。如果留空,每次构建的时间戳都会不同,不满足可复现构建的要求 - 推送 RC(Release Candidates) 版本标签 ```bash @@ -329,6 +330,15 @@ git tag -s 2.0.0-incubating-rc1 -m "release: release for 2.0.0-incubating RC1" git push origin 2.0.0-incubating-rc1 ``` +同时设置固定的构建时间戳: + +```bash +# 设置固定构建时间戳,保证每次构建产物一致 +mvn versions:set-property -Dproperty=project.build.outputTimestamp -DnewVersion=2026-09-10T00:00:00Z +# 或直接在 pom.xml 中设置: +# 2026-09-10T00:00:00Z +``` + #### 3.3.2 推送二进制包 编译预发布RC版本分支源码,并推送二进制包到 [预发仓库](https://repository.apache.org/#stagingRepositories)