[JBoss JIRA] (JBIDE-24642) Please include sha256 checksums in announcements
by Nick Boldt (JIRA)
[ https://issues.jboss.org/browse/JBIDE-24642?page=com.atlassian.jira.plugi... ]
Nick Boldt updated JBIDE-24642:
-------------------------------
Component/s: website
> Please include sha256 checksums in announcements
> ------------------------------------------------
>
> Key: JBIDE-24642
> URL: https://issues.jboss.org/browse/JBIDE-24642
> Project: Tools (JBoss Tools)
> Issue Type: Feature Request
> Components: build, website
> Reporter: Jesper Skov
> Assignee: Nick Boldt
> Fix For: LATER
>
>
> I would like to be able to verify checksums on downloaded JBoss artifacts - both EAP and eclipse-related binaries.
> Or even better, verify a signature.
> Today, when I want to use a JBossTools release, I would download
> http://download.jboss.org/jbosstools/static/oxygen/development/updates/co...
> And my only opportunity to verify the file is by downloading the sha256 file that lies next to it:
> http://download.jboss.org/jbosstools/static/oxygen/development/updates/co...
> If a hacker manages to replace the updatesite archive with compromised files, I assume they will have the brains to also update the checksum file next to it.
> So the current checksum can really only be used to verify the integrity of the downloaded file.
> Not that its contents is untampered.
> If the jar-files in the archive were signed, it would be less of an issue...
> Signed artifacts would be best. But would probably take some effort to put in place.
> A simpler remedy would be to include the checksums in the announcement. This would give an additional factor of security for those who care about that.
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
8 years, 9 months
[JBoss JIRA] (JBIDE-24641) update readme & root pom for Fuse Extras / SAP tooling to fix license, copyright
by Nick Boldt (JIRA)
[ https://issues.jboss.org/browse/JBIDE-24641?page=com.atlassian.jira.plugi... ]
Nick Boldt updated JBIDE-24641:
-------------------------------
Summary: update readme & root pom for Fuse Extras / SAP tooling to fix license, copyright (was: update readme & root pom for Fuse Extras / SAP tooling)
> update readme & root pom for Fuse Extras / SAP tooling to fix license, copyright
> --------------------------------------------------------------------------------
>
> Key: JBIDE-24641
> URL: https://issues.jboss.org/browse/JBIDE-24641
> Project: Tools (JBoss Tools)
> Issue Type: Sub-task
> Components: build, fuse-tooling
> Affects Versions: 4.5.0.AM2
> Reporter: Nick Boldt
> Assignee: Lars Heinemann
> Fix For: 4.5.0.AM2
>
>
> Had another look into the sources of https://github.com/jbosstools/jbosstools-fuse-extras and the ONLY license mention I see that isn't EPL is this:
> {quote}
> Copyright (C) 2010 FuseSource, Corp. All rights reserved.
> http://fusesource.com
> The software in this package is published under the terms of the AGPL license
> a copy of which has been included with this distribution in the license.txt file.{quote} -- https://github.com/jbosstools/jbosstools-fuse-extras/blob/master/pom.xml#...
> But there's no license.txt file, and the LICENSE file is a copy of the EPL, not a *GPL license.
> So... can someone ( [~lhein] ? [~aurelien.pupier] ?) point me to where the non-EPL sources actually are, or where non-EPL stuff is downloaded? If not, I'll update this root pom to replace Copyright FuseSource with the usual Red Hat copyright 2017, with FuseSource as an initial contributor.
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
8 years, 9 months