[jira] [Created] (OFBIZ-12186) Dependency verification

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view

[jira] [Created] (OFBIZ-12186) Dependency verification

Jacques Le Roux (Jira)
Jacques Le Roux created OFBIZ-12186:

             Summary: Dependency verification
                 Key: OFBIZ-12186
                 URL: https://issues.apache.org/jira/browse/OFBIZ-12186
             Project: OFBiz
          Issue Type: Sub-task
          Components: Gradle
    Affects Versions: Trunk
            Reporter: Jacques Le Roux

I posted a related message in dev ML: https://markmail.org/message/55r5ycn2wrbotnbn:


I just read a members thread about this article: https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610

One member mentioned that the Groovy project is using the Gradle's dependency verification feature\[1] in the Apache Groovy build.

I suggest we do the same, even after the move from JCenter to MavenCentral where things should be safer.

What do you think?

\[1] https://docs.gradle.org/current/userguide/dependency_verification.html 


This message was sent by Atlassian Jira