apache / apache/maven-wrapper

Check hashes by default

Open
#413 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Java
Stars
254
Forks
78
Avg merge
5h 26m
Merged PRs (30d)
2

Description

### New feature, improvement proposal

From docs

## Checksum verification of downloaded binaries

To avoid supply-chain-attacks by downloading a corrupted artifact, it
is possible to specify checksums for both the *maven-wrapper.jar* and
the downloaded distribution. To apply verification, add the expected
file's SHA-256 sum in hex notation, using only small caps, to
`maven-wrapper.properties`. The property for validating the
*maven-wrapper.jar* file is named `wrapperSha256Sum` whereas the
distribution file property is named `distributionSha256Sum`.

Given the increasing frequency and sophistication of supply chain attacks, we should probably just do this by default.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.