[
https://issues.apache.org/jira/browse/MNG-5689?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16417851#comment-16417851
]
Christopher Tubbs commented on MNG-5689:
----------------------------------------
bq. These days, everyone is encouraged to use a repo manager with a proxy
repository.
As long as Maven ships with a default repository already configured, and POMs
are able to specify additional repositories, it will remain necessary for users
to be able to override configuration for those repositories when they configure
a mirror to use instead of the default one or those specified in POMs. The fact
that everyone is now encouraged to use a repo manager makes this even more
important, because that is precisely the situation where configuring a mirror
matters.
> Checksum policy for mirrors
> ---------------------------
>
> Key: MNG-5689
> URL: https://issues.apache.org/jira/browse/MNG-5689
> Project: Maven
> Issue Type: Improvement
> Components: Settings
> Affects Versions: 3.2.3
> Reporter: Christopher Tubbs
> Priority: Major
> Labels: security-issue
>
> It does not appear that there is any way to configure a checksum policy for
> mirrors in the settings.xml file.
> In particular, I'd love to enforce a "strict" checksum policy on maven
> central. I can configure a mirrorOf central, but I cannot set the checksum
> policy. This seems like a big oversight.
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)