Images and publishing
Maven repositories
Mirror Maven Central or a private repository for mvn, Gradle and sbt, with the same checks as the other types.
- Settings, Registries: switch on Maven repository.
- Add a Maven registry. For Maven Central use
https://repo1.maven.org/maven2. For Nexus or Artifactory use the repository address and a token written asusername:password. - Write Maven rules on
groupId:artifactId. A*works anywhere, likeorg.apache.maven.plugins:*. Versions take2.17.2,[2.17,2.18)or2.17.*. - Developers add a mirror to
settings.xml. See Set up Maven.
- mvn downloads its own plugins through the same repository, so a new box needs allow rules for them.
org.apache.maven*,org.codehaus.plexus*and friends cover the usual ones. Audit mode shows the full list after one build. - Every file is checked against the
.sha1the repository publishes before it is kept. A file that does not match is refused. - The version list (
maven-metadata.xml) holds only allowed versions, so a range resolves to an allowed one. - A milestone or release candidate like
5.11.0-M2counts as an ordinary version, because poms pin them exactly. Snapshots are never served. - Every file is scanned for malware, checked against OSV, has its pom license read, and waits out cooling off. Auto approve and Cache now work for Maven rules too.
- Deploying with
mvn deployis not taken yet.