how to treat Exceptions in ScmResults?

2009-05-06 Thread Mark Struberg

Hi!

I'm currently implementing the maven-scm-providers-jgit and like to know how 
others did handle e.g. CheckOutScmResult for Java implemented SCM connectors. 
Especially what to do if an Exception occurred? How do you transport this 
nested Exception? fill only e.getMessage() or is there a trick I miss?

Currently I'm doing 
 return new CheckOutScmResult(, JGit clone failed., e.getMessage(),  false 
 );
but this doesn't feel ok somehow.

txs and LieGrue,
strub






SHA

2009-05-06 Thread Robert Burrell Donkin
just a heads up that maven may need to switch from SHA1 to SHA512 (or
higher). not sure how difficult that will be.

- robert

-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org



Re: SHA

2009-05-06 Thread Brett Porter
For artifact checksums? They are not a security measure, so I don't  
think increasing their length is of benefit.


Having read the same mail I'm guessing you did, it made me reflect and  
we probably should have kept using md5 for efficiency TBH.


Cheers,
Brett

On 06/05/2009, at 4:11 PM, Robert Burrell Donkin wrote:


just a heads up that maven may need to switch from SHA1 to SHA512 (or
higher). not sure how difficult that will be.

- robert

-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org




-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org



Re: [PLEASE TEST] Maven 2.2.0-RC2

2009-05-06 Thread Paul MERLIN
Le mardi 05 mai 2009 23:46:23, Brian Fox a écrit :
 What options are being passed to the release invocation? It's using -f
 which seems to be invalid.

I used the following instruction for prepare :

mvn -B release:prepare -DreleaseVersion=0.4.0 -DdevelopmentVersion=0.5.0-
SNAPSHOT



And for the release:perform, simply:

mvn release:perform




p...@dosadi ~ $ echo $MAVEN_OPTS
-Xmx512m -XX:MaxPermSize=256m


/Paul

-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org



Re: SHA

2009-05-06 Thread Robert Burrell Donkin
On Wed, May 6, 2009 at 7:27 AM, Brett Porter br...@apache.org wrote:
 For artifact checksums? They are not a security measure, so I don't think
 increasing their length is of benefit.

 Having read the same mail I'm guessing you did, it made me reflect and we
 probably should have kept using md5 for efficiency TBH.

i'm talking about http://www.debian-administration.org/users/dkg/weblog/48 etc

not really anything to panic about but going to need to transition
away from the current public key infrastructure over the next year or
so

- robert

-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org



m2eclipse embedded maven still 2.1-SNAPSHOT ?

2009-05-06 Thread nicolas de loof
Hi,
As I'm using enforcer plugin to check maven version is = 2.1.0 I just
noticed m2eclipse 0.9.8 embedded maven still reports version 2.1-SNAPSHOT
I may be wrong but AFAIK embeddedMaven is build from trunk (3.0-SNAPSHOT) -
does this mean m2eclipse uses a some-months-old version ?


Re: m2eclipse embedded maven still 2.1-SNAPSHOT ?

2009-05-06 Thread Milos Kleint
not an expert on m2eclipse but netbeans is also using a quite old version of
2.1-SNAPSHOT (from last June to be precise). The current trunk is not there
yet (and since it will take some effort to migrate I will wait for betas as
least).

I've got the same issue reported (not with enforcer, but the prerequisite
element.).
I've *fixed* the issue with faking 2.9-SNAPSHOT as version of the embedded
maven.
In any case I encourage people to use command line maven for building in
netbeans, not the embedded one.

Milos

On Wed, May 6, 2009 at 1:51 PM, nicolas de loof nico...@apache.org wrote:

 Hi,
 As I'm using enforcer plugin to check maven version is = 2.1.0 I just
 noticed m2eclipse 0.9.8 embedded maven still reports version 2.1-SNAPSHOT
 I may be wrong but AFAIK embeddedMaven is build from trunk (3.0-SNAPSHOT) -
 does this mean m2eclipse uses a some-months-old version ?



Re: m2eclipse embedded maven still 2.1-SNAPSHOT ?

2009-05-06 Thread Igor Fedorenko
This is correct, m2e 0.9.8 uses old 2.1.0 embedder from before 
2.1-3.0 version rename. We plan to update embedder to real 3.0 in 0.9.9.


For now, you should be able to move enforcer execution to a profile, 
which is not activated in m2e.


--
Regards,
Igor

nicolas de loof wrote:

Hi,
As I'm using enforcer plugin to check maven version is = 2.1.0 I just
noticed m2eclipse 0.9.8 embedded maven still reports version 2.1-SNAPSHOT
I may be wrong but AFAIK embeddedMaven is build from trunk (3.0-SNAPSHOT) -
does this mean m2eclipse uses a some-months-old version ?




-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org



Re: [PLEASE TEST] Maven 2.2.0-RC2

2009-05-06 Thread Dominic Mitchell

On 5 May 2009, at 01:02, John Casey wrote:
After finding and cleaning up some code that seems to be tainted  
during some of our efforts at generifying the codebase, we've respun  
a new release candidate.


If you have time, please give it a whirl:

https://repository.apache.org/content/repositories/maven-staging-010/org/apache/maven/apache-maven/2.2.0-RC2/

Remember, if you have any problems, report them to: http://jira.codehaus.org/browse/MNG 
 with Affects-Version: 2.2.0


...then, please reply to this thread to let me know about the  
issue! :-)


I've just noticed this whilst doing a site-deploy:

[INFO] Generating Dependencies report.
Downloading: 
http://localhost:8081/nexus/content/groups/public/com/ibm/icu/icu4j/3.4.4/icu4j-3.4.4.jar
Downloading: 
http://localhost:8081/nexus/content/groups/public/commons-lang/commons-lang/2.1/commons-lang-2.1.jar
May 6, 2009 1:58:26 PM  
hidden.org.apache.commons.httpclient.HttpMethodBase processCookieHeaders
WARNING: Cookie rejected: $Version=0;  
JSESSIONID=E545E65FB5E46552ED8473D17DF1DC80; $Path=/servlets. Illegal  
path attribute /servlets. Path of origin: /nonav/repository// 
com.google.collections/jars/google-collections-0.9.jar
May 6, 2009 1:58:30 PM  
hidden.org.apache.commons.httpclient.HttpMethodBase processCookieHeaders
WARNING: Cookie rejected: $Version=0;  
JSESSIONID=C39976B35FDA6AAE7A4C267A7DFF61D3; $Path=/servlets. Illegal  
path attribute /servlets. Path of origin: /nonav/repository// 
com.ibm.icu/jars/icu4j-3.4.4.jar


This wasn't happening on 2.1.  Is this just some debug logging left on  
by accident?


-Dom

Re: m2eclipse embedded maven still 2.1-SNAPSHOT ?

2009-05-06 Thread nicolas de loof
Is there any way to activate such a profile by detecting m2eclipse is
running (using some property) ?

2009/5/6 Igor Fedorenko i...@ifedorenko.com

 This is correct, m2e 0.9.8 uses old 2.1.0 embedder from before 2.1-3.0
 version rename. We plan to update embedder to real 3.0 in 0.9.9.

 For now, you should be able to move enforcer execution to a profile, which
 is not activated in m2e.

 --
 Regards,
 Igor


 nicolas de loof wrote:

 Hi,
 As I'm using enforcer plugin to check maven version is = 2.1.0 I just
 noticed m2eclipse 0.9.8 embedded maven still reports version 2.1-SNAPSHOT
 I may be wrong but AFAIK embeddedMaven is build from trunk (3.0-SNAPSHOT)
 -
 does this mean m2eclipse uses a some-months-old version ?



 -
 To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
 For additional commands, e-mail: dev-h...@maven.apache.org




Re: [PLEASE TEST] Maven 2.2.0-RC2

2009-05-06 Thread John Casey

This looks like a problem in the httpclient-driven http wagon.

Dominic Mitchell wrote:

On 5 May 2009, at 01:02, John Casey wrote:
After finding and cleaning up some code that seems to be tainted 
during some of our efforts at generifying the codebase, we've respun a 
new release candidate.


If you have time, please give it a whirl:

https://repository.apache.org/content/repositories/maven-staging-010/org/apache/maven/apache-maven/2.2.0-RC2/ 



Remember, if you have any problems, report them to: 
http://jira.codehaus.org/browse/MNG with Affects-Version: 2.2.0


...then, please reply to this thread to let me know about the issue! :-)


I've just noticed this whilst doing a site-deploy:

[INFO] Generating Dependencies report.
Downloading: 
http://localhost:8081/nexus/content/groups/public/com/ibm/icu/icu4j/3.4.4/icu4j-3.4.4.jar 

Downloading: 
http://localhost:8081/nexus/content/groups/public/commons-lang/commons-lang/2.1/commons-lang-2.1.jar 

May 6, 2009 1:58:26 PM 
hidden.org.apache.commons.httpclient.HttpMethodBase processCookieHeaders
WARNING: Cookie rejected: $Version=0; 
JSESSIONID=E545E65FB5E46552ED8473D17DF1DC80; $Path=/servlets. Illegal 
path attribute /servlets. Path of origin: 
/nonav/repository//com.google.collections/jars/google-collections-0.9.jar
May 6, 2009 1:58:30 PM 
hidden.org.apache.commons.httpclient.HttpMethodBase processCookieHeaders
WARNING: Cookie rejected: $Version=0; 
JSESSIONID=C39976B35FDA6AAE7A4C267A7DFF61D3; $Path=/servlets. Illegal 
path attribute /servlets. Path of origin: 
/nonav/repository//com.ibm.icu/jars/icu4j-3.4.4.jar


This wasn't happening on 2.1.  Is this just some debug logging left on 
by accident?


-Dom


-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org



Re: SHA

2009-05-06 Thread Oleg Gusakov

fyi:

- maven password encryption uses SHA-256 and switching to SHA-512 could 
be done using optional encrypted string attributes to ensure decryption 
of the existing passwords. SHA-256 is already SHA2 family and has not 
been cracked yet, so we can wait. Main question was availability of 
SHA-512 in all targeted JVMs


- Mercury signature generation uses SHA-1, I will explore switching it 
to SHA-512: http://jira.codehaus.org/browse/MERCURY-128.


Thanks,
Oleg

Robert Burrell Donkin wrote:

On Wed, May 6, 2009 at 7:27 AM, Brett Porter br...@apache.org wrote:
  

For artifact checksums? They are not a security measure, so I don't think
increasing their length is of benefit.

Having read the same mail I'm guessing you did, it made me reflect and we

probably should have kept using md5 for efficiency TBH.



i'm talking about http://www.debian-administration.org/users/dkg/weblog/48 etc

not really anything to panic about but going to need to transition
away from the current public key infrastructure over the next year or
so

- robert

-
To unsubscribe, e-mail: dev-unsubscr...@maven.apache.org
For additional commands, e-mail: dev-h...@maven.apache.org