dnsbtchr commented on issue #13385: URL: https://github.com/apache/maven/issues/13385#issuecomment-6075608296
Hi @cstamas, thanks for the quick response. The problem described in the link is indeed exactly what we see. What I don't understand yet is why it only started failing with 3.10.0 then. The document says > Since 2.0.21, Resolver protects itself against this failure mode: when an auto-discovered prefixes file denies a path, the very first denial per remote repository is verified against the remote repository itself using a lightweight existence check. If the repository actually serves the denied path, the auto-discovered prefixes file is provably wrong for that path; a warning naming the repository is emitted (report it to the repository administrator) and, since 2.0.22, only that verified path is allowed while the prefixes file stays enforcing for all other paths So I'd expect this behavior to kick in and most likely it did up until 3.10.0. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
