elharo opened a new pull request, #256:
URL: https://github.com/apache/maven-artifact-plugin/pull/256

   Fixes https://github.com/apache/maven-artifact-plugin/issues/249
   
   `renderReproducibleCentralArtifact()` interpolated `groupId`, `artifactId` 
and `version` straight from the POM into the Reproducible Central badge and 
link URLs. Coordinates are arbitrary user input for third-party projects, and 
characters such as `&`, `?`, `#`, `"` or `/` produced a broken/misleading badge 
as well as potentially malformed/foreign HTML in the generated site report.
   
   This change URL-encodes each coordinate segment (UTF-8) when building both 
URLs:
   
   - badge: 
`https://img.shields.io/reproducible-central/artifact/{groupId}/{artifactId}/{version}?labelColor=1e5b96`
   - link: 
`https://jvm-repo-rebuild.github.io/reproducible-central/badge/artifact/{groupId
 path}/{artifactId}.html`
   
   The group-id path still maps dots to `/` after encoding.
   
   ### Test
   Added `ReproducibleCentralReportTest` with unit tests asserting that special 
characters in coordinates are percentage-encoded in the generated URLs. The 
tests were verified to fail on the unpatched code and pass with the fix.
   
   All 4 unit tests pass; checkstyle, spotless and RAT are clean.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to