Details
Description
gradle-witness [1] aims to provide insulation against MITM attacks via maven dependency downloads. From the looks of things, it would require a pretty small amount of upfront work and upkeep to integrate this and prevent injection of rogue code.
Attachments
Issue Links
- is cloned by
-
AURORA-1997 Consider using checksum-dependency-plugin for dependency verification
- Closed
- is related to
-
AURORA-618 Pin cryptographic checksums of python requirements
- Resolved
-
AURORA-620 Consider using JCenter over HTTPS instead of Maven Central
- Resolved