[ 
https://issues.apache.org/jira/browse/XERCESJ-1794?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18074249#comment-18074249
 ] 

Elliotte Rusty Harold commented on XERCESJ-1794:
------------------------------------------------

FYI, I have been told there are ongoing discussions about hardening Apache 
projects against supply chain attacks. I haven't been participating in those 
discussion myself. I'm not sure what they are and aren't considering. Might be 
worth participating if anyone has time.

> Make Build Reproducible
> -----------------------
>
>                 Key: XERCESJ-1794
>                 URL: https://issues.apache.org/jira/browse/XERCESJ-1794
>             Project: Xerces2-J
>          Issue Type: Improvement
>          Components: Build
>    Affects Versions: 2.12.3
>            Reporter: Elliotte Rusty Harold
>            Priority: Critical
>
> This is increasingly important to avoid and mitigate supply chain attacks.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to