[ 
https://issues.apache.org/jira/browse/MNG-5689?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16414056#comment-16414056
 ] 

Christopher Tubbs commented on MNG-5689:
----------------------------------------

Ah, understood. That could work. I haven't tested it. It might work as a 
workaround, if it applies globally, but it's still better to be able to 
configure repositories in the configuration files.

If {{ -C }} works, maybe a simpler design would be to add a top-level 
{{<globalChecksumPolicy/>}} which corresponds to that command-line option?

> Checksum policy for mirrors
> ---------------------------
>
>                 Key: MNG-5689
>                 URL: https://issues.apache.org/jira/browse/MNG-5689
>             Project: Maven
>          Issue Type: Improvement
>          Components: Settings
>    Affects Versions: 3.2.3
>            Reporter: Christopher Tubbs
>            Priority: Major
>              Labels: security-issue
>
> It does not appear that there is any way to configure a checksum policy for 
> mirrors in the settings.xml file.
> In particular, I'd love to enforce a "strict" checksum policy on maven 
> central. I can configure a mirrorOf central, but I cannot set the checksum 
> policy. This seems like a big oversight.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to