Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

SHA-256 validation fails when unzip is unavailable because distribution format is silently changed to .tar.gz

Open
#425 1 comment 4 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

@simono is already working on this.

Since Jul 23, 2026.

  • #435 by @simono — open

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
shell
Domain
build-system

Research direction

Start with the unzip fallback in mvnw and the distributionSha256Sum setting in maven-wrapper.properties. Reproduce the failure without unzip, then trace how the configured checksum is applied after the distribution URL changes. The issue is resolved when checksum validation works correctly for the distribution downloaded in that environment.

Written by the indexing model from the issue text.

Description

When unzip is not installed, mvnw silently rewrites the distributionUrl from .zip to .tar.gz

if ! command -v unzip >/dev/null; then
  distributionUrl="${distributionUrl%.zip}.tar.gz"
  distributionUrlName="${distributionUrl##*/}"
fi

(from # Apache Maven Wrapper startup batch script, version 3.3.4)

However, the distributionSha256Sum validation on still runs against the configured checksum, which was computed for the .zip file. The .tar.gz has a different checksum, so validation always fails with:

Error: Failed to validate Maven distribution SHA-256, your Maven distribution might be compromised.
If you updated your Maven version, you need to update the specified distributionSha256Sum property.

This appears to be to be a design issue – the distibution is either zip or tar.gz but there is only ever a single distributionSha256Sum property. What is the reasong for this design? There inevitably need to be a sha sum configured for each downloadable distribution.

Steps to reproduce

  1. Configure maven-wrapper.properties with distributionSha256Sum for the .zip distribution
  2. Run ./mvnw in an environment without unzip (e.g. eclipse-temurin Docker image)
  3. Build fails with SHA-256 validation error

Expected behavior

Described above.

Environment

  • Maven Wrapper 3.3.4
  • eclipse-temurin:25 Docker image (Ubuntu 26.04, no unzip, no wget/curl)

Workaround

Install unzip in the environment before running mvnw, e.g. in Containerfile

# Install unzip required by Maven Wrapper to download the .zip distribution;
# without it, mvnw downloads .tar.gz which doesn't match distributionSha256Sum
RUN apt-get update && apt-get install -y unzip
Dominant language
Java
Stars
254
Forks
78
Avg merge
23h 36m
Merged PRs (30d)
8

Getting set up

  • No Dockerfile or Docker Compose file
  • Has a pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/maven-wrapper

All issues in apache/maven-wrapper

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.