Security Question

2007-08-30 Thread Joel Morris
We have just upgraded to the latest version of Archiva and I have a couple of security questions. 1. In the previous release we added our archiva repository to our ~/.m2/settings.xml as a mirror. ... catchy EBS Maven Repository Manager http:///archiva/repository/i

Re: Security question about remote repositories.

2004-09-30 Thread Martin Skopp
On Wed, 2004-09-29 at 18:38, Helck, Christopher wrote: > Maven makes it very easy to download and use jars off the web. I think > this is good, but a security expert has raised some concerns about it. I remind a discussion about that issue either here or on the developer list. Maybe you find more

RE: Security question about remote repositories.

2004-09-29 Thread Carlos Sanchez
> -Original Message- > From: Helck, Christopher [mailto:[EMAIL PROTECTED] > Sent: Wednesday, September 29, 2004 10:09 PM > To: Maven Users List > Subject: RE: Security question about remote repositories. > > Ok, in no particular order, and most concerns are not n

RE: Security question about remote repositories.

2004-09-29 Thread Helck, Christopher
Original Message- From: Carlos Sanchez [mailto:[EMAIL PROTECTED] Sent: Wednesday, September 29, 2004 3:34 PM To: 'Maven Users List' Subject: RE: Security question about remote repositories. Also I'd like to hear those concerns. > -Original Message- > From:

RE: Security question about remote repositories.

2004-09-29 Thread Carlos Sanchez
Also I'd like to hear those concerns. > -Original Message- > From: Helck, Christopher [mailto:[EMAIL PROTECTED] > Sent: Wednesday, September 29, 2004 8:39 PM > To: Maven Users List > Subject: Security question about remote repositories. > > > Maven makes

RE: Security question about remote repositories.

2004-09-29 Thread Carlos Sanchez
Christopher [mailto:[EMAIL PROTECTED] > Sent: Wednesday, September 29, 2004 8:39 PM > To: Maven Users List > Subject: Security question about remote repositories. > > > Maven makes it very easy to download and use jars off the > web. I think this is good, but a security ex

Security question about remote repositories.

2004-09-29 Thread Helck, Christopher
Maven makes it very easy to download and use jars off the web. I think this is good, but a security expert has raised some concerns about it. Can anyone suggest a set of policies to use when determining which packages to use and how/when to download them? I'm thinking along the lines of creating a