You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@maven.apache.org by Tomo Suzuki <su...@google.com.INVALID> on 2020/05/22 16:04:07 UTC

slf4j-jcl-1.0.1: Checksum validation failed

Hi Maven users,

Does anyone know why slf4j-jcl-1.0.1's checksum is invalid in Maven Central?

I'm investigating the following warning message:

[WARNING] Could not validate integrity of download from
https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom:
Checksum validation failed, expected
7035ae7774a9a082a316a6943bbad9dfab6319b3 but is
c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21

When I checked
https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom.sha1,
it has

7035ae7774a9a082a316a6943bbad9dfab6319b3
 /home/projects/maven/repository-staging/to-ibiblio/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom

However, curl and sha1sum say otherwise:

suztomo@suztomo:~/spring-cloud-gcp$ curl
https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
|sha1sum
  % Total    % Received % Xferd  Average Speed   Time    Time     Time
 Current
                                 Dload  Upload   Total   Spent    Left
 Speed
100   394  100   394    0     0   4061      0 --:--:-- --:--:-- --:--:--
 4104
c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21  -

So from my perspective, the discrepancy is in line with the Maven warning
message. Maven Central is hosting invalid checksum files. Does anyone know
why this discrepancy happens slf4j-jcl-1.0.1?

-- 
Regards,
Tomo

Re: slf4j-jcl-1.0.1: Checksum validation failed

Posted by Tomo Suzuki <su...@google.com.INVALID>.
The discrepancy has been resolved as per the ticket.

On Tue, May 26, 2020 at 10:15 PM Tomo Suzuki <su...@google.com> wrote:

> Hi Olivier,
>
> Thank you for your response! I just created a ticket for them:
> https://issues.sonatype.org/browse/MVNCENTRAL-5833
>
> On Sun, May 24, 2020 at 04:56 Olivier Lamy <ol...@apache.org> wrote:
>
>> Maven Central is managed by Sonatype read term of services
>> https://repo1.maven.org/terms.html
>>
>> You should report this issue here
>> https://issues.sonatype.org/projects/MVNCENTRAL
>>
>> On Sat, 23 May 2020 at 02:04, Tomo Suzuki <su...@google.com.invalid>
>> wrote:
>>
>> > Hi Maven users,
>> >
>> > Does anyone know why slf4j-jcl-1.0.1's checksum is invalid in Maven
>> > Central?
>> >
>> > I'm investigating the following warning message:
>> >
>> > [WARNING] Could not validate integrity of download from
>> >
>> >
>> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
>> > :
>> > Checksum validation failed, expected
>> > 7035ae7774a9a082a316a6943bbad9dfab6319b3 but is
>> > c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21
>> >
>> > When I checked
>> >
>> >
>> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom.sha1
>> > ,
>> > it has
>> >
>> > 7035ae7774a9a082a316a6943bbad9dfab6319b3
>> >
>> >
>> /home/projects/maven/repository-staging/to-ibiblio/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
>> >
>> > However, curl and sha1sum say otherwise:
>> >
>> > suztomo@suztomo:~/spring-cloud-gcp$ curl
>> >
>> >
>> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
>> > |sha1sum
>> > <
>> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom%7Csha1sum
>> >
>> >   % Total    % Received % Xferd  Average Speed   Time    Time     Time
>> >  Current
>> >                                  Dload  Upload   Total   Spent    Left
>> >  Speed
>> > 100   394  100   394    0     0   4061      0 --:--:-- --:--:-- --:--:--
>> >  4104
>> > c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21  -
>> >
>> > So from my perspective, the discrepancy is in line with the Maven
>> warning
>> > message. Maven Central is hosting invalid checksum files. Does anyone
>> know
>> > why this discrepancy happens slf4j-jcl-1.0.1?
>> >
>> > --
>> > Regards,
>> > Tomo
>> >
>>
>>
>> --
>> Olivier Lamy
>> http://twitter.com/olamy | http://linkedin.com/in/olamy
>>
>

-- 
Regards,
Tomo

Re: slf4j-jcl-1.0.1: Checksum validation failed

Posted by Tomo Suzuki <su...@google.com.INVALID>.
Hi Olivier,

Thank you for your response! I just created a ticket for them:
https://issues.sonatype.org/browse/MVNCENTRAL-5833

On Sun, May 24, 2020 at 04:56 Olivier Lamy <ol...@apache.org> wrote:

> Maven Central is managed by Sonatype read term of services
> https://repo1.maven.org/terms.html
>
> You should report this issue here
> https://issues.sonatype.org/projects/MVNCENTRAL
>
> On Sat, 23 May 2020 at 02:04, Tomo Suzuki <su...@google.com.invalid>
> wrote:
>
> > Hi Maven users,
> >
> > Does anyone know why slf4j-jcl-1.0.1's checksum is invalid in Maven
> > Central?
> >
> > I'm investigating the following warning message:
> >
> > [WARNING] Could not validate integrity of download from
> >
> >
> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
> > :
> > Checksum validation failed, expected
> > 7035ae7774a9a082a316a6943bbad9dfab6319b3 but is
> > c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21
> >
> > When I checked
> >
> >
> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom.sha1
> > ,
> > it has
> >
> > 7035ae7774a9a082a316a6943bbad9dfab6319b3
> >
> >
> /home/projects/maven/repository-staging/to-ibiblio/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
> >
> > However, curl and sha1sum say otherwise:
> >
> > suztomo@suztomo:~/spring-cloud-gcp$ curl
> >
> >
> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
> > |sha1sum
> > <
> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom%7Csha1sum
> >
> >   % Total    % Received % Xferd  Average Speed   Time    Time     Time
> >  Current
> >                                  Dload  Upload   Total   Spent    Left
> >  Speed
> > 100   394  100   394    0     0   4061      0 --:--:-- --:--:-- --:--:--
> >  4104
> > c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21  -
> >
> > So from my perspective, the discrepancy is in line with the Maven warning
> > message. Maven Central is hosting invalid checksum files. Does anyone
> know
> > why this discrepancy happens slf4j-jcl-1.0.1?
> >
> > --
> > Regards,
> > Tomo
> >
>
>
> --
> Olivier Lamy
> http://twitter.com/olamy | http://linkedin.com/in/olamy
>

Re: slf4j-jcl-1.0.1: Checksum validation failed

Posted by Olivier Lamy <ol...@apache.org>.
Maven Central is managed by Sonatype read term of services
https://repo1.maven.org/terms.html

You should report this issue here
https://issues.sonatype.org/projects/MVNCENTRAL

On Sat, 23 May 2020 at 02:04, Tomo Suzuki <su...@google.com.invalid>
wrote:

> Hi Maven users,
>
> Does anyone know why slf4j-jcl-1.0.1's checksum is invalid in Maven
> Central?
>
> I'm investigating the following warning message:
>
> [WARNING] Could not validate integrity of download from
>
> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
> :
> Checksum validation failed, expected
> 7035ae7774a9a082a316a6943bbad9dfab6319b3 but is
> c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21
>
> When I checked
>
> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom.sha1
> ,
> it has
>
> 7035ae7774a9a082a316a6943bbad9dfab6319b3
>
>  /home/projects/maven/repository-staging/to-ibiblio/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
>
> However, curl and sha1sum say otherwise:
>
> suztomo@suztomo:~/spring-cloud-gcp$ curl
>
> https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom
> |sha1sum
> <https://repo1.maven.org/maven2/org/slf4j/slf4j-jcl/1.0.1/slf4j-jcl-1.0.1.pom%7Csha1sum>
>   % Total    % Received % Xferd  Average Speed   Time    Time     Time
>  Current
>                                  Dload  Upload   Total   Spent    Left
>  Speed
> 100   394  100   394    0     0   4061      0 --:--:-- --:--:-- --:--:--
>  4104
> c5c0a3fff6071a4c720f1b7aa1b66cb9d0b26a21  -
>
> So from my perspective, the discrepancy is in line with the Maven warning
> message. Maven Central is hosting invalid checksum files. Does anyone know
> why this discrepancy happens slf4j-jcl-1.0.1?
>
> --
> Regards,
> Tomo
>


-- 
Olivier Lamy
http://twitter.com/olamy | http://linkedin.com/in/olamy