MSHADE-147: Add flag to disable jar signing verification#122
Open
gzsombor wants to merge 1 commit intoapache:masterfrom
Open
MSHADE-147: Add flag to disable jar signing verification#122gzsombor wants to merge 1 commit intoapache:masterfrom
gzsombor wants to merge 1 commit intoapache:masterfrom
Conversation
Contributor
|
A test would be welcomed. |
|
Hey i'm running into this trying to shade one of my projects and I think not only this should be finished and we should get the option to avoid this but we also need the logging to be more than a generic "Invalid signature file digest for Manifest main attributes". If you're going to tell me one or more of my dependencies has an invalid signature you should at least tell me which ones so I can take action over that instead of filtering out the signature files of all my dependencies as if they had no use |
|
This should be merged, I'm having the same problem. |
|
Resolve #509 |
1 similar comment
|
Resolve #509 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is the rebased fix for https://issues.apache.org/jira/browse/MSHADE-147.
The problem is, that certain jar files has an incorrect signature, so the shade plugin couldn't even open it.
The solution for this, is a flag, which can disable this jar verification optionally.
Following this checklist to help us incorporate your
contribution quickly and easily:
for the change (usually before you start working on it). Trivial changes like typos do not
require a JIRA issue. Your pull request should address just this issue, without
pulling in other changes.
[MSHADE-XXX] - Fixes bug in ApproximateQuantiles,where you replace
MSHADE-XXXwith the appropriate JIRA issue. Best practiceis to use the JIRA issue title in the pull request title and in the first line of the
commit message.
mvn clean verifyto make sure basic checks pass. A more thorough check willbe performed on your pull request automatically.
mvn -Prun-its clean verify).If your pull request is about ~20 lines of code you don't need to sign an
Individual Contributor License Agreement if you are unsure
please ask on the developers list.
To make clear that you license your contribution under
the Apache License Version 2.0, January 2004
you have to acknowledge this by using the following check-box.
I hereby declare this contribution to be licenced under the Apache License Version 2.0, January 2004
In any other case, please file an Apache Individual Contributor License Agreement.