SHA-256 validation fails when unzip is unavailable because distribution format is silently changed to .tar.gz
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- shell
- Domain
- build-system
Research direction
Start with the unzip fallback in mvnw and the distributionSha256Sum setting in maven-wrapper.properties. Reproduce the failure without unzip, then trace how the configured checksum is applied after the distribution URL changes. The issue is resolved when checksum validation works correctly for the distribution downloaded in that environment.
Written by the indexing model from the issue text.
Description
When unzip is not installed, mvnw silently rewrites the distributionUrl from .zip to .tar.gz
if ! command -v unzip >/dev/null; then
distributionUrl="${distributionUrl%.zip}.tar.gz"
distributionUrlName="${distributionUrl##*/}"
fi
(from # Apache Maven Wrapper startup batch script, version 3.3.4)
However, the distributionSha256Sum validation on still runs against the configured checksum, which was computed for the .zip file. The .tar.gz has a different checksum, so validation always fails with:
Error: Failed to validate Maven distribution SHA-256, your Maven distribution might be compromised.
If you updated your Maven version, you need to update the specified distributionSha256Sum property.
This appears to be to be a design issue – the distibution is either zip or tar.gz but there is only ever a single distributionSha256Sum property. What is the reasong for this design? There inevitably need to be a sha sum configured for each downloadable distribution.
Steps to reproduce
- Configure
maven-wrapper.propertieswithdistributionSha256Sumfor the.zipdistribution - Run
./mvnwin an environment withoutunzip(e.g.eclipse-temurinDocker image) - Build fails with SHA-256 validation error
Expected behavior
Described above.
Environment
- Maven Wrapper 3.3.4
eclipse-temurin:25Docker image (Ubuntu 26.04, nounzip, nowget/curl)
Workaround
Install unzip in the environment before running mvnw, e.g. in Containerfile
# Install unzip required by Maven Wrapper to download the .zip distribution;
# without it, mvnw downloads .tar.gz which doesn't match distributionSha256Sum
RUN apt-get update && apt-get install -y unzip
- Dominant language
- Java
- Stars
- 254
- Forks
- 78
- Avg merge
- 23h 36m
- Merged PRs (30d)
- 8
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/maven-wrapper
-
mvnw.cmd selects the last matching extracted directory while mvnw selects the firstPossibly taken @tanvir-ux claimed this 34 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
apache/maven-wrapper#442 ·
Maintainers usually reply within 1 day
-
priority:trivial
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
apache/maven-wrapper#280 · 1 comment · 1 reaction ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 68/100
apache/maven-wrapper#454 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
apache/maven-wrapper#441 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 55/100
apache/maven-wrapper#424 · 1 comment ·
Maintainers usually reply within 1 day
All issues in apache/maven-wrapper
Similar issues
-
enhancement
Difficulty 1/5 Under an hour Newbie friendliness 88/100
helidon-io/helidon#12721 ·
Maintainers usually reply within 1 day
-
status: team-only type: dependency-upgrade
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
spring-projects/spring-boot#51966 ·
Maintainers usually reply within 1 day
-
Missing repro Platform: Android
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
software-mansion/react-native-reanimated#10816 · 2 comments ·
Maintainers usually reply within 1 day
-
area/docs backport/26.6 backport/26.8 kind/bug status/triage
Difficulty 1/5 Under an hour Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
[destination-snowflake] Custom domains rejected unlike source connectionsPossibly taken @kuza55 claimed this today. Openautoteam community connectors/destination/snowflake team/use
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day