-
Notifications
You must be signed in to change notification settings - Fork 28
add Reproducible Central Report #292
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
uh, looking at example, it seems badges are now blocked by csp (were not less than one month ago) |
|
ok, researching: I suppose some more restrictive CSP have been configured ASF-wide, need to find a pointer... |
|
https://infra.apache.org/csp.html supposed to be become effective March 1, 2025. |
|
https://privacy.apache.org/policies/website-policy.html
this may be that one that has been enabled over the past month |
|
@niallkp do you confirm that maven.apache.org webserver csp has been updated during last month to enforce that "4. Using Assets from other Domains" restriction, please? |
@hboutemy Infra were going to implement the CSP temporarily on 1st February (yesterday) for testing purposes - but its not supposed to go permanently live until 1st March 2025. Heres the email with the plan (I think you need to be logged in to PonyMail to see): I don't know if Infra have turned that on or not for testing - would need to ask them. |
slawekjaranowski
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
First we need a confirm with INFRA tema ... so now I remove from next release proposition
| The value will be updated by Maven Release Plugin during releases. If a project wants to disable Reproducible Builds, just define | ||
| the property value with any single non-numeric character. | ||
|
|
||
| In version 34, Reproducible Central Report is added to report on Reproducible Builds checks for the project and it dependencies. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"and its dependencies" ?!
see sample report https://maven.apache.org/plugins/maven-artifact-plugin/reproducible-central.html