Check hashes by default
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 38/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- java
- Domain
- build-system, security
Research direction
Start with the checksum-verification section in the issue and the maven-wrapper.properties entries wrapperSha256Sum and distributionSha256Sum. Read the existing Maven Wrapper handling for maven-wrapper.jar and the downloaded distribution, then determine how expected SHA-256 values should be supplied when verification is enabled by default. Done means both artifacts are checked by default without relying on an unspecified opt-in.
Written by the indexing model from the issue text.
Description
New feature, improvement proposal
From docs
Checksum verification of downloaded binaries
To avoid supply-chain-attacks by downloading a corrupted artifact, it
is possible to specify checksums for both the maven-wrapper.jar and
the downloaded distribution. To apply verification, add the expected
file's SHA-256 sum in hex notation, using only small caps, to
maven-wrapper.properties. The property for validating the
maven-wrapper.jar file is named wrapperSha256Sum whereas the
distribution file property is named distributionSha256Sum.
Given the increasing frequency and sophistication of supply chain attacks, we should probably just do this by default.
- Dominant language
- Java
- Stars
- 254
- Forks
- 78
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 5
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/maven-wrapper
-
mvnw.cmd selects the last matching extracted directory while mvnw selects the firstPossibly taken @tanvir-ux claimed this 32 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
apache/maven-wrapper#442 ·
-
priority:trivial
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
apache/maven-wrapper#280 · 1 comment · 1 reaction ·
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 68/100
apache/maven-wrapper#454 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
apache/maven-wrapper#441 · 1 comment ·
-
SHA-256 validation fails when unzip is unavailable because distribution format is silently changed to .tar.gzPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 4/5 3-5 days Newbie friendliness 48/100
apache/maven-wrapper#425 · 1 comment · 4 reactions ·
All issues in apache/maven-wrapper
Similar issues
-
[Bug] The shared instance selector's placeholder and no-match text ignore the display languagePossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
apache/rocketmq-dashboard#5561 ·
Maintainers usually reply within 3 days
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
HMCL-dev/HMCL#6934 · 1 comment ·
Maintainers usually reply within 1 day
-
test(setup): GitHub configuration tests fail when the temp path is long enough for YAML foldingOpenbug good first issue help wanted priority medium size S
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
martin-francois/symphony-trello#776 · 1 comment ·
Maintainers usually reply within 1 day
-
Console.printHexOpengood first issue kernel
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
JackFurton/who-would-build-a-kernel-in-java#33 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100