[freenet-dev] Sonar analysis of Freenet builds

2011-05-06 Thread Matthew Toseland
On Sunday 01 May 2011 20:10:24 Ian Clarke wrote: > On Sat, Apr 30, 2011 at 3:31 PM, recursor.net>wrote: > > > The repo poisoning issue is a canard - Maven checks the hashes and sig's > > > > Checking hashes and signatures is hardly a cast-iron guarantee against Maven > repo poisoning. If

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-05-06 Thread Matthew Toseland
On Sunday 01 May 2011 20:10:24 Ian Clarke wrote: On Sat, Apr 30, 2011 at 3:31 PM, freenet.10.technomat...@recursor.netwrote: The repo poisoning issue is a canard - Maven checks the hashes and sig's Checking hashes and signatures is hardly a cast-iron guarantee against Maven repo

[freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 02/05/11 19:28, Ximin Luo wrote: > On 02/05/11 19:23, Ximin Luo wrote: >> On 30/04/11 21:31, freenet.10.technomation at recursor.net wrote: >>> I took *freenet-official* and ran it through Maven, findbugs and Sonar. I >>> offlined a couple of screenshots ( >>>

[freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 02/05/11 19:23, Ximin Luo wrote: > On 30/04/11 21:31, freenet.10.technomation at recursor.net wrote: >> I took *freenet-official* and ran it through Maven, findbugs and Sonar. I >> offlined a couple of screenshots ( >>

[freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 30/04/11 21:31, freenet.10.technomation at recursor.net wrote: > I took *freenet-official* and ran it through Maven, findbugs and Sonar. I > offlined a couple of screenshots ( > https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar1.png, >

[freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 01/05/11 00:56, Thomas Sachau wrote: > Am 30.04.2011 22:31, schrieb freenet.10.technomation at recursor.net: >> Also, the archives being >> used in Freenet are probably built using Maven. > > How do you get to this conclusion? >> >> Another big plus with reorging the build, apart from making

[freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 30/04/11 21:31, freenet.10.technomation at recursor.net wrote: > I took *freenet-official* and ran it through Maven, findbugs and Sonar. I > offlined a couple of screenshots ( > https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar1.png, >

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 30/04/11 21:31, freenet.10.technomat...@recursor.net wrote: I took *freenet-official* and ran it through Maven, findbugs and Sonar. I offlined a couple of screenshots ( https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar1.png,

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 01/05/11 00:56, Thomas Sachau wrote: Am 30.04.2011 22:31, schrieb freenet.10.technomat...@recursor.net: Also, the archives being used in Freenet are probably built using Maven. How do you get to this conclusion? Another big plus with reorging the build, apart from making the structure

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 30/04/11 21:31, freenet.10.technomat...@recursor.net wrote: I took *freenet-official* and ran it through Maven, findbugs and Sonar. I offlined a couple of screenshots ( https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar1.png,

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 02/05/11 19:23, Ximin Luo wrote: On 30/04/11 21:31, freenet.10.technomat...@recursor.net wrote: I took *freenet-official* and ran it through Maven, findbugs and Sonar. I offlined a couple of screenshots ( https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar1.png,

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-05-02 Thread Ximin Luo
On 02/05/11 19:28, Ximin Luo wrote: On 02/05/11 19:23, Ximin Luo wrote: On 30/04/11 21:31, freenet.10.technomat...@recursor.net wrote: I took *freenet-official* and ran it through Maven, findbugs and Sonar. I offlined a couple of screenshots (

[freenet-dev] Sonar analysis of Freenet builds

2011-05-01 Thread Ian Clarke
On Sat, Apr 30, 2011 at 3:31 PM, wrote: > The repo poisoning issue is a canard - Maven checks the hashes and sig's > Checking hashes and signatures is hardly a cast-iron guarantee against Maven repo poisoning. If someone can slip a subtle vulnerability into the source of any Maven dependency

[freenet-dev] Sonar analysis of Freenet builds

2011-05-01 Thread Thomas Sachau
Am 30.04.2011 22:31, schrieb freenet.10.technomation at recursor.net: > Also, the archives being > used in Freenet are probably built using Maven. How do you get to this conclusion? > > Another big plus with reorging the build, apart from making the structure > easier to grok, simpler and more

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-05-01 Thread Ian Clarke
On Sat, Apr 30, 2011 at 3:31 PM, freenet.10.technomat...@recursor.netwrote: The repo poisoning issue is a canard - Maven checks the hashes and sig's Checking hashes and signatures is hardly a cast-iron guarantee against Maven repo poisoning. If someone can slip a subtle vulnerability into the

[freenet-dev] Sonar analysis of Freenet builds

2011-04-30 Thread freenet.10.technomat...@recursor.net
I took *freenet-official* and ran it through Maven, findbugs and Sonar. I offlined a couple of screenshots ( https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar1.png, https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar2.png), and the top five layers of the

[freenet-dev] Sonar analysis of Freenet builds

2011-04-30 Thread freenet . 10 . technomation
I took *freenet-official* and ran it through Maven, findbugs and Sonar. I offlined a couple of screenshots ( https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar1.png, https://github.com/SebastianWeetabix/fred-maven/blob/master/freenetsonar2.png), and the top five layers of the

Re: [freenet-dev] Sonar analysis of Freenet builds

2011-04-30 Thread Thomas Sachau
Am 30.04.2011 22:31, schrieb freenet.10.technomat...@recursor.net: Also, the archives being used in Freenet are probably built using Maven. How do you get to this conclusion? Another big plus with reorging the build, apart from making the structure easier to grok, simpler and more