[
https://issues.apache.org/jira/browse/CXF-8913?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18073792#comment-18073792
]
Claus Ibsen commented on CXF-8913:
----------------------------------
Thanks Colm.
Yeah the best solution is to maske it optional. So much appreciated your work.
As you can see from the last link from Aurelien then they will prioritize their
commercial customers and we risk the open source community cannot access this
library.
Also many companies that use Camel and CXF have restrictions on what can be
downloaded and would not allow to let their systems download from a 3rd party
repo like this one from Atlassian.
Its the only repo left and would be great to get rid of so its just download
from maven central in the true open source spirit.
> Avoid 3rd party maven repository for OpenSAML
> ---------------------------------------------
>
> Key: CXF-8913
> URL: https://issues.apache.org/jira/browse/CXF-8913
> Project: CXF
> Issue Type: Improvement
> Components: WS-* Components
> Affects Versions: 4.0.2
> Reporter: Claus Ibsen
> Assignee: Colm O hEigeartaigh
> Priority: Major
>
> Apache CXF depends on OpenSAML from Apache WSSJ project
> However this commit causes wss4j to download JARs from NOT maven central but
> from
> https://build.shibboleth.net/nexus/content/groups/public
> https://github.com/apache/ws-wss4j/commit/e4a33efcb2b474a1da2b2c08f815b2718e111823
> Is there a way for Apache CXF to only use JARs from maven central. There is a
> trust issue when JARs are NOT downloaded from central.
> At Apache Camel we only download from maven central - except for camel-jira
> which sadly had to download from Atlassian. We are considering deprecating
> and removing this component for that reason.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)