Re: [VOTE] Move to Attic

2024-01-30 Thread Martin
Hi, +1 Regards Martin Am Dienstag, 30. Januar 2024, 02:19:42 CET schrieb Olivier Lamy: > Hi, > It's more of a procedural vote, as this has already been discussed and agreed. > > Moving to Attic > > +1 > -1 (please provide ideas to restart some activities) > &g

[ANN] Apache Archiva 2.2.7 released

2021-12-22 Thread Martin
The Apache Archiva team is pleased to announce the release of Archiva 2.2.7 Archiva is available for download from the web site. http://archiva.apache.org/download.cgi Archiva is an application for managing one or more remote repositories, including administration, artifact handling, brow

[ANN] Apache Archiva 2.2.6 released

2021-12-15 Thread Martin
The Apache Archiva team is pleased to announce the release of Archiva 2.2.6 Archiva is available for download from the web site. http://archiva.apache.org/download.cgi Archiva is an application for managing one or more remote repositories, including administration, artifact handling, brows

Re: archiva-security-audit.log remains empty

2021-06-26 Thread Martin
t the immediateFlush="true" attribute on the appender. Sorry for that. Regards Martin Am Samstag, 26. Juni 2021, 14:45:39 CEST schrieb Bram Van Dam: > Greetings, > > I'm running Archiva 2.2.5 and I'm having some difficulty getting audit > logging to work. > >

[SECURITY] CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection

2020-06-19 Thread Martin
CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Archiva all versions before 2.2.5 By providing special values to the archiva login form a attacker is able to retrieve user attribu

[ANN] Apache Archiva 2.2.5 released

2020-06-19 Thread Martin
The Apache Archiva team is pleased to announce the release of Archiva 2.2.5 Archiva is available for download from the web site. http://archiva.apache.org/download.cgi Archiva is an application for managing one or more remote repositories, including administration, artifact handling, brows

Re: How Can I regist NAS HDDD as Alias?

2020-04-16 Thread Martin
Hi, I think you wrote to the wrong mailing list. This list is about Apache Archiva, a artifact repository, not about the HTTPD server. Please have a look at: https://httpd.apache.org/ https://httpd.apache.org/lists.html Regards Martin Am Dienstag, 14. April 2020, 02:29:45 CEST schrieb

Re: Question about Archiva

2020-04-16 Thread Martin
or have questions, don't hesitate to ask. Regards Martin Am Montag, 13. April 2020, 16:43:32 CEST schrieb Karl Heinz Marbaise: > Hi, > > currently I'm writing a Test tool[1] for Maven Plugins etc. I want to > know if there is an option to use Archiva as Repository Man

[SECURITY] CVE-2019-0214: Apache Archiva arbitrary file write and delete on the server

2019-04-30 Thread Martin
CVE-2019-0214: Apache Archiva arbitrary file write and delete on the server Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Apache Archiva 2.0.0 - 2.2.3 The unsupported versions 1.x are also affected. It is possible to write files to the archiva server at ar

[SECURITY] CVE-2019-0213: Apache Archiva Stored XSS

2019-04-30 Thread Martin
CVE-2019-0213: Apache Archiva Stored XSS Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Archiva 2.0.0 - 2.2.3 The unsupported versions 1.x are also affected. It may be possible to store malicious XSS code into central configuration entries, i.e. the lo

[ANN] Apache Archiva 2.2.4 released

2019-04-30 Thread Martin
The Apache Archiva team is pleased to announce the release of Archiva 2.2.4. Archiva is available for download from the web site. Archiva is an application for managing one or more remote repositories, including administration, artifact handling, browsing and searching. If you have any quest

Re: Binaries distributable for Archiva 2.2.4

2019-04-30 Thread Martin Stockhammer
Hi, will be published in the next days. But it's only a bugfix release. No new features. Regards Martin Am 29. April 2019 21:25:33 MESZ schrieb "Mirabito, Massimo (Max) (CDC/DDID/NCHHSTP/OD) (CTR)" : >Dear All, > >We are running Archiva V2.2.3 on Windows. I just

Re: Archiva Security

2018-11-28 Thread Martin
the web ui before. Please logout before testing with your browser. The better alternative is to test with curl or wget, both do not send cookies by default. Regards Martin Am Dienstag, 27. November 2018, 07:25:28 CET schrieb ranjithmnair: > Hi, > I am using Archiva, and when i inc

Re: Interested in a Docker Image & Kubernetes Chart?

2018-10-23 Thread Martin Stockhammer
Hi Terence, great! Start with small contributions to get an understanding how the process works. For getting bigger changes into the project the dev mailing list is the best place to start discussing about the details. Regards Martin Am 22. Oktober 2018 21:34:24 MESZ schrieb Terence Kent

Re: Interested in a Docker Image & Kubernetes Chart?

2018-10-20 Thread Martin
like, you can even add the complete docker/kubernetes part as pull request. If you have any questions, don't hesitate to ask. Regards Martin Am Samstag, 20. Oktober 2018, 01:30:41 CEST schrieb Terence Kent: > Hey Martin, > > Feel free to add a link to our image and chart

Re: deleting old snapshots

2018-10-19 Thread Martin
g" action on the repository. If you activate debug log, you should see entries from the "RepositoryPurgeConsumer" in archiva.log. Regards Martin Am Freitag, 19. Oktober 2018, 19:22:01 CEST schrieb Terence Kent: > Stefaan, Matthew, > > I hate "works for me respons

Re: Interested in a Docker Image & Kubernetes Chart?

2018-10-19 Thread Martin
ion so, if there is development going on, it may be broken every now and then, so it may be not a good idea, if the file is downloaded dynamically during container start/build. Regards Martin Am Freitag, 19. Oktober 2018, 02:08:52 CEST schrieb Terence Kent: > Hello, > > In early 2015,

Re: deleting old snapshots

2018-10-19 Thread Martin Stockhammer
? Regards Martin Am 19. Oktober 2018 15:39:54 MESZ schrieb Matthew Broadhead : >yes i have activated the "repository-purge" consumer under Repository >scanning -> Consumers.  maybe i also need to activate the >"validate-checksums" consumer as that is t

Re: Help with AD LDAP config in 2.2.3

2018-09-27 Thread Martin
Hi, I'm not sure, but maybe https://issues.apache.org/jira/browse/MRM-1866 can help. Do you have both Ldap and Database repository configured? Regards Martin Am Mittwoch, 26. September 2018, 21:16:11 CEST schrieb Candreva, Chris: > After beating my head against the LDAP config, I fina

Re: Problems with REST API getting artifacts.

2018-03-24 Thread Martin
the artifact on the web UI with the given entries? Is there any info in the log file? If not, could you please change it to debug level, and send it to me? Greetings Martin Am Mittwoch, 21. März 2018, 21:54:26 CET schrieb Maury Hammel: > Hello, I have just getting into Archiva and am having p

Re: DefaultFileLockManager & Lock

2017-11-22 Thread Martin
Hi, I'm not sure, what you want to know exactly about these classes. This is a file lock, so there can only exist one lock per file. Please formulate a more detailed question. Maybe I can help then. Greetings Martin P.S: Is '二毛' your name? Am Dienstag, 14. November 201

Re: Need help configuring Archiva LDAP configuration with anonymous snapshot deploy

2017-11-01 Thread Martin
useful help. Feel free to create a JIRA ticket for both (or a pull request). Greetings Martin Am Dienstag, 31. Oktober 2017, 09:19:13 CET schrieb stefaan.du...@roularta.be: > Hello, > > Sorry for my late response. (vacation followed by other priorities at work) > After we finaly

Re: Need help configuring Archiva LDAP configuration with anonymous snapshot deploy

2017-08-28 Thread Martin
you think the security risk is acceptable. Please look at the release notes. Greetings Martin Am Dienstag, 22. August 2017, 11:50:48 CEST schrieb Stefaan Dutry: > In our current setup we only use the LDAP configuration to > authenticate and not for authorisation. > > We would like

Re: Error 403 when proxying with Nginx

2017-08-14 Thread Martin Pola
I didn't receive the reply from Mr. Lamy, but I was able to read it in the WWW archives of this mailing list. Thanks to both of you! It looks like the issue was caused by Archiva's CSRF prevention filter. Setting rest.baseUrl resolved the it. - Martin On lördag 12 augusti 2017 kl

Re: Error 403 when proxying with Nginx

2017-08-12 Thread Martin
Hi Martin, do you use the current version? Archiva 2.2.3? There is a CSRF-prevention filter active. You have to add the URL of your nginx server to the rest.baseUrl field (you may set a comma separated list for multiple URLs). See http://archiva.apache.org/docs/2.2.3/release-notes.html Note

Error 403 when proxying with Nginx

2017-08-12 Thread Martin Pola
proceed to resolve it? Kind regards, Martin Pola

Re: help with upgrade -- CSRF / Redback / proxy

2017-05-31 Thread Martin Stockhammer
Hi, it is mentioned in the release notes. But not clear enough, I think. I will improve the docs. Greetings Martin Am 1. Juni 2017 05:02:14 MESZ schrieb Adam Brin : >Martin, >Thank you, that really helped. It might be nice to identify some of >this >in the upgrade notes

Re: help with upgrade -- CSRF / Redback / proxy

2017-05-31 Thread Martin
http://dev.server.com:9 ... ... Info about configuration files can be found at: http://archiva.apache.org/docs/2.2.3/adminguide/configuration-files.html Greetings Martin Am Mittwoch, 31. Mai 2017, 21:41:02 CEST schrieb Niranjan Babu Bommu: > I had same problem whe

[SECURITY] CVE-2017-5657: Apache Archiva CSRF vulnerability for REST endpoints

2017-05-19 Thread Martin
CVE-2017-5657: Apache Archiva CSRF vulnerabilities for various REST endpoints Severity: Important Vendor: The Apache Software Foundation Versions Affected: Archiva 2.0.0 - 2.2.1 The unsupported versions 1.x are also affected. Several REST service endpoints of Apache Archiva are not pr

[ANN] Apache Archiva 2.2.3 Released

2017-05-17 Thread Martin
The Apache Archiva team is pleased to announce the release of Archiva 2.2.3. Archiva is available for download from the web site. Archiva is an application for managing one or more remote repositories, including administration, artifact handling, browsing and searching. If you have any quest

Re: How to enforce SSL with trusted letsencrypt.org certificate in Apache Archiva standalone 2.2.1?

2017-05-08 Thread Martin
configuration, you may use the WAR file of archiva and deploy it on a tomcat server. Greetings Martin Am Sonntag, 7. Mai 2017, 14:56:34 CEST schrieb Karl-Philipp Richter: > Hi, > I'd like to use/enforce SSL with a trusted letsencrypt.org certificate > for an Apache Archiva standalone

Re: archiva dependency graph/tree in snapshot repository not shown

2016-12-23 Thread Martin
u may provide a pull request. Greetings Martin Am Donnerstag, 22. Dezember 2016, 12:28:58 CET schrieb Bachmair Florian - flexSolution GmbH: > Hi! > > Is there a way to view the dependency graph/tree for artifacts in the > snapshot repository? > If I deploy the same project to the rel

Re: Rebuilding the repository

2016-10-16 Thread Martin
Remove /repositories completely start archiva Rescan Directories I'm not sure, if this works and/or if this leads to other errors, but at least with a out of the box archiva standalone the repositories directory is rebuilt after the restart. Greetings Martin Am Montag, 10. Oktober 2016,

Re: Rebuilding the repository

2016-09-22 Thread Martin Stockhammer
Hi Marco, a rescan (directories scanning action) does not help? For 2: would be great if you can create a issue in the Jira. Greetings Martin Am 22. September 2016 17:13:55 MESZ, schrieb m...@mherrn.de: >Hello, > >I see lots of problems in the archiva.log that the process cannot f

Re: Archiva to Attic? Asking contribution

2016-09-12 Thread Martin Stockhammer
andable (great work!). So if I can help, feel free to contact me. I'm subscribed to the mailing lists already. Greetings Martin > Hi everyone, > I'm a bit sad to say I don't have anymore a lot of time to contribute to > the project. > We have a very limited nu

Re: Beginner needs help with Archiva

2011-07-19 Thread Julien Martin
name of the managed repository under > which > you wish to copy all your m2 repository > If you do not have a managed repository, you can create one using the > Archiva UI. > > Once the copy is done, you can force Archiva d/b scan on the managed > repository. > > Hope this

Beginner needs help with Archiva

2011-07-19 Thread Julien Martin
Hello, I am new to Archiva which I have successfully installed and I would like to know how to add my local "~/.m2" repository to Archiva if that makes sense at all. Can anyone please help? Thanks in advance, Julien.

Re: WELCOME to users@archiva.apache.org

2011-06-21 Thread Martin Schwarzbauer
Thank u very very much! Now it's working! Martin 2011/6/20 Wendy Smoak > On Mon, Jun 20, 2011 at 11:59 AM, Martin Schwarzbauer > wrote: > > Hi Wendy, > > no i don't have any other settings in the settings.xml (except a HTTP > > Proxy). > > > > W

Re: WELCOME to users@archiva.apache.org

2011-06-20 Thread Martin Schwarzbauer
Hi Wendy, no i don't have any other settings in the settings.xml (except a HTTP Proxy). What's missing? Martin 2011/6/20 Wendy Smoak > On Fri, Jun 17, 2011 at 5:44 AM, Martin Schwarzbauer > wrote: > > > > My settings.xml: > > > > intern

Re: WELCOME to users@archiva.apache.org

2011-06-20 Thread Martin Schwarzbauer
t right here - like incorrect > access permissions on the repository, or incorrect credentials on the maven > end if you meant it to be restricted? > > - Brett > > On 20/06/2011, at 5:05 PM, Martin Schwarzbauer wrote: > > > The directory in the repo looks like: > > .

Re: WELCOME to users@archiva.apache.org

2011-06-20 Thread Martin Schwarzbauer
at org.sonatype.aether.impl.internal.DefaultArtifactResolver.resolve(DefaultArtifactResolver.java:531) ... 26 more [ERROR] [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/DependencyResolutionException Thx, Mar

Re: WELCOME to users@archiva.apache.org

2011-06-19 Thread Martin Schwarzbauer
I tried this, this doesn't work for me! 2011/6/20 Brett Porter > The simplest is to remove the false when you > deploy so that the snapshots are deployed with a timestamp & build number. > > On 20/06/2011, at 2:57 PM, Martin Schwarzbauer wrote: > > > Hello Brett, &

Re: WELCOME to users@archiva.apache.org

2011-06-19 Thread Martin Schwarzbauer
m the repo! Why? How to handle this? Thx, Martin 2011/6/20 Brett Porter > Sorry, I'm a bit unclear what you are trying to do here with the snapshot. > Is it your objective to use a timestamp (in which case, you need to change > the snapshotRepository in your distributionManagemen

Re: WELCOME to users@archiva.apache.org

2011-06-17 Thread Martin Schwarzbauer
ven3! Can anybody help me? thx, Martin 2011/6/14 Mohni, Daniel > Hi Martin > > Questions 1: Is this url available in a web browser ? > > > http://febuild1/archiva/repository/internal/at/sprecher/web/rest/service/WebService/1.0-SNAPSHOT/WebService-1.0-SNAPSHOT.pom > > Qu

Re: WELCOME to users@archiva.apache.org

2011-06-14 Thread Martin Schwarzbauer
Hi Daniel! No the URL is not available in browser. I have tried to add the internal deploy.snapshot repo as a proxy connector to the internal repo - this doesn't work too! Martin 2011/6/14 Mohni, Daniel > Hi Martin > > Questions 1: Is this url available in a web browse

Re: WELCOME to users@archiva.apache.org

2011-06-14 Thread Martin Schwarzbauer
Archiva? Thx in advance, Martin

archiva consumer test cases

2009-04-27 Thread martin . goldhahn
org.eclipse.jdt.internal.junit.runner.RemoteTestRunner.main(RemoteTestRunner.java:196) I think the same happens with the archiva-consumer-plugin in the sandbox. What am I missing here? Cheers Martin

Re: Uploading POM

2009-01-19 Thread Martin Höller
ption. Set false in your pom.xml to disable this feature. hth, - martin signature.asc Description: PGP signature

Re: fileupload.FileUploadBase size

2008-11-26 Thread Martin Cooper
chiva uses Commons FileUpload directly, so it must be through some other dependency. Not sure what that is, so I'm not sure how much control you have over it. Perhaps another Archivan can chime in here. -- Martin Cooper On Wed, Nov 26, 2008 at 5:57 PM, Chris Anders <[EMAIL PRO

Re: fileupload.FileUploadBase size

2008-11-26 Thread Martin Cooper
mmons/fileupload/FileUploadBase.html#setFileSizeMax(long) http://commons.apache.org/fileupload/apidocs/org/apache/commons/fileupload/disk/DiskFileItemFactory.html#setSizeThreshold(int) -- Martin Cooper On Wed, Nov 26, 2008 at 5:25 PM, Chris Anders <[EMAIL PROTECTED]>wrote: > >