Analysis on Maven projects failing due to certificate validation error against Maven Central artefacts
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
At some point in the last week CodeQL jobs across our repositories started failing. Sampling our repositories Action history this starting happening approximately 4-5 days ago e.g.

Note that it's hard to pinpoint an exact point in time where this happened as repositories have varying levels of activity. There is no common factor of change that we can identify across these repositories. Some of the failures were triggered by our developers opening PR, but others were triggered by automated PRs from tools like Dependabot (e.g. the 3rd example job below). For repositories where no builds have been triggered, or no PRs opened in the time window, then we see no failures and the most recent run from 5+ days ago was successful.
The following are some example failing jobs across several repositories, and branches thereof, in our organisation:
- https://github.com/telicent-oss/smart-caches-core/actions/runs/12947315333/job/36224632277
- https://github.com/telicent-oss/smart-caches-core/actions/runs/12947315333/job/36224632277
- https://github.com/telicent-oss/rdf-abac/actions/runs/12976261418/job/36188305613
Looking in the job logs we see a bunch of errors from CodeQL, but looking through the job logs the root cause looks to be the following:
> [2025-01-27 13:31:57] [build-stdout] [2025-01-27 13:31:57] [autobuild] The following artifacts could not be resolved: org.apache.maven.plugins:maven-assembly-plugin:pom:3.7.1 (absent): Could not transfer artifact org.apache.maven.plugins:maven-assembly-plugin:pom:3.7.1 from/to central (https://repo.maven.apache.org/maven2): PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
For some reason the CodeQL job/tools doesn't seem to have the right certificates available to verify the certificate of Maven Central?? Thus it won't download the Maven dependencies and fails the entire job.
A quick check in my browser shows that the certificate on `repo.maven.apache.org` appears valid AFAICT:

What's going on here?
Hướng dẫn đóng góp
Hướng nghiên cứu
Start with the linked GitHub Actions runs and their CodeQL job logs, focusing on the Maven Central certificate-validation errors and failed dependency resolution. Compare the affected runs with the earlier successful runs to identify what changed; done means the cause is established and a reproducible remediation is documented.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- github-actions, java
- Lĩnh vực
- build-system, ci-cd, security
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 25/100