[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [VOTE] Policies for managing Beam dependencies


Thank you for driving these decisions. I would make a meta-point, all other recent votes and if passes this one could be converted to web site documents at some point in an easily accessible and linkable way.

On Wed, Jun 6, 2018 at 4:53 PM, Chamikara Jayalath <chamikara@xxxxxxxxxx> wrote:
Hi All,

We recently had a discussion regarding managing Beam dependencies. Please see [1] for the email thread and [2] for the relevant document.

This discussion resulted in following policies. I believe, these will help keep Beam at a healthy state while allowing human intervention when needed.

(1) Human readable reports on status of Beam dependencies are generated weekly and shared with the Beam community through the dev list.

(2) Beam components should define dependencies and their versions at the top level.

(3) A significantly outdated dependency (identified manually or through tooling) should result in a JIRA that is a blocker for the next release. Release manager may choose to push the blocker to the subsequent release or downgrade from a blocker.

(4) Dependency declarations may identify owners that are responsible for upgrading the respective dependencies.

(5) Dependencies of Java SDK components that may cause issues to other components if leaked should be shaded.

Please vote:
[ ] +1, Approve that we adapt these policies
[ ] -1, Do not approve (please provide specific comments)