[ https://issues.apache.org/jira/browse/MPOM-118?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15304628#comment-15304628 ]
Christopher Tubbs commented on MPOM-118: ---------------------------------------- Isn't it true that this attribute is inherited? So, not only would it try to do a harmless merge to the ASF parent parent (which doesn't exist), it would also trigger child POMs to do a merge with the ASF parent. Right? (In any case, this is an area where the overall maven docs could benefit from some more examples/clarification.) > Enforce strong GPG signatures by default > ---------------------------------------- > > Key: MPOM-118 > URL: https://issues.apache.org/jira/browse/MPOM-118 > Project: Maven POMs > Issue Type: Improvement > Components: asf > Affects Versions: ASF-17 > Reporter: Christopher Tubbs > Fix For: ASF-19 > > > maven-gpg-plugin configuration could be improved a bit so that ASF releases > are not weakened by a user's weak personal configuration. > I suggest adding something like the following to maven-gpg-plugin's > configuration in the pluginManagement section: > {code:xml} > <gpgArguments combine.children="append"> > <arg>--digest-algo=SHA512</arg> > </gpgArguments> > {code} -- This message was sent by Atlassian JIRA (v6.3.4#6332)