github / github/codeql

Analysis on Maven projects failing due to certificate validation error against Maven Central artefacts

Open
#18,598 4 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

At some point in the last week CodeQL jobs across our repositories started failing. Sampling our repositories Action history this starting happening approximately 4-5 days ago e.g.

![Image](https://github.com/user-attachments/assets/3c7296bb-f4de-467e-93a4-cf1049cf52a4)

Note that it's hard to pinpoint an exact point in time where this happened as repositories have varying levels of activity. There is no common factor of change that we can identify across these repositories. Some of the failures were triggered by our developers opening PR, but others were triggered by automated PRs from tools like Dependabot (e.g. the 3rd example job below). For repositories where no builds have been triggered, or no PRs opened in the time window, then we see no failures and the most recent run from 5+ days ago was successful.

The following are some example failing jobs across several repositories, and branches thereof, in our organisation:

- https://github.com/telicent-oss/smart-caches-core/actions/runs/12947315333/job/36224632277
- https://github.com/telicent-oss/smart-caches-core/actions/runs/12947315333/job/36224632277
- https://github.com/telicent-oss/rdf-abac/actions/runs/12976261418/job/36188305613

Looking in the job logs we see a bunch of errors from CodeQL, but looking through the job logs the root cause looks to be the following:

> [2025-01-27 13:31:57] [build-stdout] [2025-01-27 13:31:57] [autobuild] The following artifacts could not be resolved: org.apache.maven.plugins:maven-assembly-plugin:pom:3.7.1 (absent): Could not transfer artifact org.apache.maven.plugins:maven-assembly-plugin:pom:3.7.1 from/to central (https://repo.maven.apache.org/maven2): PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

For some reason the CodeQL job/tools doesn't seem to have the right certificates available to verify the certificate of Maven Central?? Thus it won't download the Maven dependencies and fails the entire job.

A quick check in my browser shows that the certificate on `repo.maven.apache.org` appears valid AFAICT:

![Safari Certificate Details for repo.maven.apache.org](https://github.com/user-attachments/assets/e2c15cf7-3766-45b5-a28c-15d35f9fa377)

What's going on here?

Contributor guide

Open the contributing guide

Research direction

Start with the linked GitHub Actions runs and their CodeQL job logs, focusing on the Maven Central certificate-validation errors and failed dependency resolution. Compare the affected runs with the earlier successful runs to identify what changed; done means the cause is established and a reproducible remediation is documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, java
Domain
build-system, ci-cd, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.