[ https://issues.apache.org/jira/browse/MNG-5689?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16414056#comment-16414056 ]
Christopher Tubbs commented on MNG-5689: ---------------------------------------- Ah, understood. That could work. I haven't tested it. It might work as a workaround, if it applies globally, but it's still better to be able to configure repositories in the configuration files. If {{ -C }} works, maybe a simpler design would be to add a top-level {{<globalChecksumPolicy/>}} which corresponds to that command-line option? > Checksum policy for mirrors > --------------------------- > > Key: MNG-5689 > URL: https://issues.apache.org/jira/browse/MNG-5689 > Project: Maven > Issue Type: Improvement > Components: Settings > Affects Versions: 3.2.3 > Reporter: Christopher Tubbs > Priority: Major > Labels: security-issue > > It does not appear that there is any way to configure a checksum policy for > mirrors in the settings.xml file. > In particular, I'd love to enforce a "strict" checksum policy on maven > central. I can configure a mirrorOf central, but I cannot set the checksum > policy. This seems like a big oversight. -- This message was sent by Atlassian JIRA (v7.6.3#76005)