Enable Maven dependency checksum verification

Description

Implement checksum verification for Maven dependencies in Lucee to enhance security and integrity of downloaded artifacts.

Technical Requirements:

  1. Allow defining expected checksums in dependency declarations

  2. Compare defined checksum against downloaded artifact checksum

  3. Maintain existing verification between header checksum and file-generated checksum

  4. Support common checksum algorithms (SHA-1, SHA-256, MD5)

Activity

Michael Offner 27 January 2025 at 15:11

Michael Offner 27 January 2025 at 15:11

doc updated

Fixed

Details

Assignee

Reporter

Labels

New Issue warning screen

Before you create a new Issue, please post to the mailing list first https://dev.lucee.org

Once the issue has been verified, one of the Lucee team will ask you to file an issue

Sprint

Fix versions

Priority

Created 26 January 2025 at 09:59
Updated 3 February 2025 at 16:08
Resolved 3 February 2025 at 16:08