www-repository mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Wendy Smoak" <wsm...@gmail.com>
Subject Re: maven-repository/org/apache/myfaces/core/..../1.1.2
Date Tue, 20 Jun 2006 22:13:16 GMT
I know Sean and Henk have already discussed this.  It was definitely
unintentional.  In any case, Sean is very busy right now, and asked if
I could help set things right.

To fix it, my intent is to replace the changed files with the
'originals' from ibiblio.  That should get the original jar/md5/sha1
files back, and the jar will match the .asc from April 15th again.

Any objections? Is there a better way to handle it?

Thanks,
-- 
Wendy Smoak

On 6/20/06, Henk P. Penning <henkp@apache.org> wrote:
> Hi,
>
>   It appears that on www.apache.org/dist some files changed :
>
>     dir  maven-repository/org/apache/myfaces/core/myfaces-api/1.1.2
>     file myfaces-api-1.1.2.jar
>
>     dir  maven-repository/org/apache/myfaces/core/myfaces-impl/1.1.2/
>     file myfaces-impl-1.1.2.jar
>
>   The md5's changed and the corresponding sigs (.asc's) are BAD.
>   Btw, the jar.asc's are much older than the .jar's.
>
>   The file owner is 'schof' (Sean Schofield) but since the files are
>   group writable, it is unclear if 'schof' is responsible. In fact
>   the files are group writable by 'apcvs', so it could be any of a
>   1000+ comitters. Brr.
>
>   This is not the first time there is a problem in this area.
>   Please fix theses problems real soon, and please take proper
>   measures to prevent such problems in the future.
>
>   For details, see
>
>     http://people.apache.org/~henkp/checker/sig.html
>     http://people.apache.org/~henkp/checker/md5.html
>
>   Thanks,
>
>   Henk Penning
>
> ----------------------------------------------------------------   _
> Henk P. Penning, Computer Systems Group       R Uithof CGN-A232  _/ \_
> Dept of Computer Science, Utrecht University  T +31 30 253 4106 / \_/ \
> Padualaan 14, 3584CH Utrecht, the Netherlands F +31 30 251 3791 \_/ \_/
> http://www.cs.uu.nl/~henkp/                   M penning@cs.uu.nl  \_/
>
>

Mime
View raw message