You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The maven wrapper supports checking the SHA256 sum of the downloaded maven distribution. To harden security we should put the sha256 hash into maven-wrapper.properties.
The text was updated successfully, but these errors were encountered:
This means that the included SHA256 might be wrong when the download URL for the binaries for Maven gets switched to .tar.gz.
It ultimately seems like this might be a deficiency in the Maven wrapper, since it doesn't seem to me that you can specify SHA256 sums for both of the possible downloads that could occur (one for .tar.gz and one for .zip).
The maven wrapper supports checking the SHA256 sum of the downloaded maven distribution. To harden security we should put the sha256 hash into
maven-wrapper.properties
.The text was updated successfully, but these errors were encountered: