Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Have different warning types for different events when validating lockfile #689

Open
yogyagamage opened this issue Apr 2, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@yogyagamage
Copy link
Collaborator

Currently, maven-lockfile validation gives the same warning when,

  • A package download has been tampered with
  • A package version has changed

As suggested by Rhys, a user might want to be protected against tampered packages rather than legitimate version updates. So, we can have different warnings for these cases, to make it clear.

@yogyagamage yogyagamage added the enhancement New feature or request label Apr 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant