apache / apache/maven-resolver

docs/ste-expected-checksums trusted vs integrity verification

Open
#2,042 0 comments 0 reactions 0 assignees View on GitHub
bug documentation
Dominant language
Java
Stars
152
Forks
160
Avg merge
1d 4h
Merged PRs (30d)
49

Description

### Affected version

HEAD

### Bug description

There are internal contradictions in this document about the purposes of checksums. Trusted checksums are not just about integrity verification. And this extends to some other docs too.

This needs to be straightened out

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the docs/ste-expected-checksums document and identify the statements that distinguish trusted checksums from integrity verification. Search the related documentation mentioned in the issue for the same contradiction; done means the explanations consistently describe the purposes of both checksum uses.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.