[
https://issues.apache.org/jira/browse/XERCESJ-1794?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18074249#comment-18074249
]
Elliotte Rusty Harold commented on XERCESJ-1794:
------------------------------------------------
FYI, I have been told there are ongoing discussions about hardening Apache
projects against supply chain attacks. I haven't been participating in those
discussion myself. I'm not sure what they are and aren't considering. Might be
worth participating if anyone has time.
> Make Build Reproducible
> -----------------------
>
> Key: XERCESJ-1794
> URL: https://issues.apache.org/jira/browse/XERCESJ-1794
> Project: Xerces2-J
> Issue Type: Improvement
> Components: Build
> Affects Versions: 2.12.3
> Reporter: Elliotte Rusty Harold
> Priority: Critical
>
> This is increasingly important to avoid and mitigate supply chain attacks.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]