Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address "Signed release" check from clomonitor #109

Closed
toddbaert opened this issue Oct 3, 2022 · 1 comment
Closed

Address "Signed release" check from clomonitor #109

toddbaert opened this issue Oct 3, 2022 · 1 comment
Assignees

Comments

@toddbaert
Copy link
Member

toddbaert commented Oct 3, 2022

see: #83

│ Security / Signed release            ┆      ✗     │

We think this is because the github release only includes source archives and no signed jars. We DO indeed sign jars pushed to maven central, so likely this can be resolved several ways. If possible, the best would probably be to attach the jars (even though they are published to maven).

cc @justinabrahms

@justinabrahms
Copy link
Member

We've just fixed the tool to allow us to explicitly disable this check since we solve it w/ maven.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants