Hadoop QA commented on ZOOKEEPER-2594:
-1 overall. Here are the results of testing the latest attachment
against trunk revision ec20c5434cc8a334b3fd25e27d26dccf4793c8f3.
+1 @author. The patch does not contain any @author tags.
-1 tests included. The patch doesn't appear to include any new or modified
Please justify why no new tests are needed for this
Also please list what manual steps were performed to
verify this patch.
+1 javadoc. The javadoc tool did not generate any warning messages.
+1 javac. The applied patch does not increase the total number of javac
+1 findbugs. The patch does not introduce any new Findbugs (version 2.0.3)
+1 release audit. The applied patch does not increase the total number of
release audit warnings.
+1 core tests. The patch passed core unit tests.
+1 contrib tests. The patch passed contrib unit tests.
This message is automatically generated.
> Use TLS for downloading artifacts during build
> Key: ZOOKEEPER-2594
> URL: https://issues.apache.org/jira/browse/ZOOKEEPER-2594
> Project: ZooKeeper
> Issue Type: Improvement
> Components: build
> Affects Versions: 3.4.9, 3.5.2
> Reporter: Olaf Flebbe
> Assignee: Olaf Flebbe
> Priority: Blocker
> Labels: security
> Fix For: 3.4.10, 3.5.3, 3.6.0
> Attachments: 0001-ZOOKEEPER-2594-Use-TLS-for-downloading.patch,
> Zookeeper builds are downloading dependencies using the insecure http://
> An outdated java.net repository can be removed now, since its content is now
> on maven.org.
> The https://repo2.maven.org cannot be used, since its certificate is invalid.
> Use repo1.maven.org instead (IMHO this is intentional).
> Appended you'll find a proposed patch (against git head) to fix these issues,
> for a starter.
This message was sent by Atlassian JIRA