Re: [SECURITY] Dependency Confusion

2021-02-27 Thread Jacques Le Roux
Hi Amit, Yes it's related to https://issues.apache.org/jira/browse/OFBIZ-12186 It's now disabled because it seems it only works on my local machine for now Please follow https://ci.apache.org/builders/ofbizTrunkFramework Jacques Le 27/02/2021 à 14:37, Amit Gadaley a écrit : Hello All, I am

Re: [SECURITY] Dependency Confusion

2021-02-27 Thread Amit Gadaley
Hello All, I am not 100% sure following errors are related to this thread or not, but I have updated my trunk branches of both, ofbiz-framework and plugins, repositories. And after that I am unable to clean and build ofbiz. Here are the error logs from my local server:

Re: [SECURITY] Dependency Confusion

2021-02-23 Thread Jacques Le Roux
Forgot this one: https://central.sonatype.org/pages/ossrh-guide.html Le 23/02/2021 à 12:41, Jacques Le Roux a écrit : Hi Michael, Yes I see no other ways, not sure how to do it. I found : https://discuss.gradle.org/t/host-gradle-wrapper-distributions-on-maven-central/543/2

Re: [SECURITY] Dependency Confusion

2021-02-23 Thread Jacques Le Roux
Hi Michael, Yes I see no other ways, not sure how to do it. I found : https://discuss.gradle.org/t/host-gradle-wrapper-distributions-on-maven-central/543/2 https://stackoverflow.com/questions/42908823/publish-to-sonatype-using-new-gradle-plugin-maven-publish Jacques Le 23/02/2021 à 08:53,

Re: [SECURITY] Dependency Confusion

2021-02-22 Thread Michael Brohl
Hi Jacques, all, we should try to publish the Gradle Wrapper to Maven Central, right? Regards, Michael Brohl ecomify GmbH - www.ecomify.de Am 22.02.21 um 14:08 schrieb Jacques Le Roux: Hi, I created https://issues.apache.org/jira/browse/OFBIZ-12186 for that. It's much more simple that I

Re: [SECURITY] Dependency Confusion

2021-02-22 Thread Jacques Le Roux
Hi, I created https://issues.apache.org/jira/browse/OFBIZ-12186 for that. It's much more simple that I feared. I'll soon commit the attached verification-metadata.xml file there, if nobody oppose. We will later need to update it when updating dependencies. So I'll also update