github / github/codeql

Analysis on Maven projects failing due to certificate validation error against Maven Central artefacts

Offen
#18,598 4 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

At some point in the last week CodeQL jobs across our repositories started failing. Sampling our repositories Action history this starting happening approximately 4-5 days ago e.g.

![Image](https://github.com/user-attachments/assets/3c7296bb-f4de-467e-93a4-cf1049cf52a4)

Note that it's hard to pinpoint an exact point in time where this happened as repositories have varying levels of activity. There is no common factor of change that we can identify across these repositories. Some of the failures were triggered by our developers opening PR, but others were triggered by automated PRs from tools like Dependabot (e.g. the 3rd example job below). For repositories where no builds have been triggered, or no PRs opened in the time window, then we see no failures and the most recent run from 5+ days ago was successful.

The following are some example failing jobs across several repositories, and branches thereof, in our organisation:

- https://github.com/telicent-oss/smart-caches-core/actions/runs/12947315333/job/36224632277
- https://github.com/telicent-oss/smart-caches-core/actions/runs/12947315333/job/36224632277
- https://github.com/telicent-oss/rdf-abac/actions/runs/12976261418/job/36188305613

Looking in the job logs we see a bunch of errors from CodeQL, but looking through the job logs the root cause looks to be the following:

> [2025-01-27 13:31:57] [build-stdout] [2025-01-27 13:31:57] [autobuild] The following artifacts could not be resolved: org.apache.maven.plugins:maven-assembly-plugin:pom:3.7.1 (absent): Could not transfer artifact org.apache.maven.plugins:maven-assembly-plugin:pom:3.7.1 from/to central (https://repo.maven.apache.org/maven2): PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

For some reason the CodeQL job/tools doesn't seem to have the right certificates available to verify the certificate of Maven Central?? Thus it won't download the Maven dependencies and fails the entire job.

A quick check in my browser shows that the certificate on `repo.maven.apache.org` appears valid AFAICT:

![Safari Certificate Details for repo.maven.apache.org](https://github.com/user-attachments/assets/e2c15cf7-3766-45b5-a28c-15d35f9fa377)

What's going on here?

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the linked GitHub Actions runs and their CodeQL job logs, focusing on the Maven Central certificate-validation errors and failed dependency resolution. Compare the affected runs with the earlier successful runs to identify what changed; done means the cause is established and a reproducible remediation is documented.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
github-actions, java
Bereich
build-system, ci-cd, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.