apache / apache/grails-core

[INITIATIVE] Decommissioning HTTP Artifact Servers

Open
#11,412 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Groovy
Stars
2.9k
Forks
975
Avg merge
1d 22h
Merged PRs (30d)
92

Description

Hi Grails Team,

This is a follow up to my article I published back in June of this year.

[![mitm_build](https://user-images.githubusercontent.com/1323708/59226671-90645200-8ba1-11e9-8ab3-39292bef99e9.jpeg)](https://medium.com/@jonathan.leitschuh/want-to-take-over-the-java-ecosystem-all-you-need-is-a-mitm-1fc329d898fb?source=friends_link&sk=3c99970c55a899ad9ef41f126efcde0e)
[Want to take over the Java ecosystem? All you need is a MITM!](https://medium.com/@jonathan.leitschuh/want-to-take-over-the-java-ecosystem-all-you-need-is-a-mitm-1fc329d898fb?source=friends_link&sk=3c99970c55a899ad9ef41f126efcde0e)

In an effort to clamp down on this industry-wide vulnerability, I'm pushing forward an initiative where the biggest artifact hosts are dropping support for HTTP against their artifact servers on January 15th, 2020. From that point forward we are hoping to only support HTTPS.

The current list of organizations participating can be found here:
https://gist.github.com/JLLeitschuh/789e49e3d34092a005031a0a1880af99

I'm currently working on the Gradle announcement.

I'm wondering if the Grails team would be willing to participate in this initiative.

Currently, a fuzzy GitHub search finds over 40k uses of the Grails artifact server over HTTP instead of HTTPS: https://github.com/search?l=Groovy&q=http%3A%2F%2Frepo.grails.org&type=Code

This would impact your repository here: http://repo.grails.org

---
As an aside: I also reccomend that you setup support for HTTPS redirects for the following sites:

- http://docs.grails.org
- http://grails.org/plugins

Contributor guide

Open the contributing guide

Research direction

The issue names no repository files or tests. Start by reviewing the referenced HTTPS initiative, the repo.grails.org HTTP usage, and the listed Grails sites; done would require a defined decision on participation and an agreed scope for HTTPS-only artifact access and redirects.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
infrastructure, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.