Add sha256 and sha256_src attributes to maven_jar #9237
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
..and print warnings if sha256 or sha256_src aren't used, like this:
The warning message is designed to be copy paste-able directly into the WORKSPACE file.
#6799
#8880
RELNOTES: Added
sha256
andsha256_src
attributes tomaven_jar
. Please consider migrating to SHA-256 as SHA-1 has been deemed cryptographically insecure (https://shattered.io). Or, userules_jvm_external
to manage your transitive Maven dependencies with artifact pinning and SHA-256 verification support.