<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On 11 Mar 2015, at 17:29, Brent Putman &lt;<a href="mailto:putmanb@georgetown.edu" class="">putmanb@georgetown.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><div class="">
  
    <meta content="text/html; charset=windows-1252" http-equiv="Content-Type" class="">
  
  <div bgcolor="#FFFFFF" text="#000000" class="">"Minor Version Release Process", step 10 b:<br class="">
    <br class="">
    <blockquote type="cite" class="">
      <meta http-equiv="content-type" content="text/html;
        charset=windows-1252" class="">
      Copy the distribution archive, its md5 and sha1 hashes, and PGP
      signature to a version-named directory in the download site. You
      can verify the signature(s) at this point.</blockquote></div></div></blockquote><div><br class=""></div><div>Thanks, I guess my eye slid over that for some reason.</div><div><br class=""></div><blockquote type="cite" class=""><div class=""><div bgcolor="#FFFFFF" text="#000000" class="">I was also wondering (starting looking in Maven docs and got
    sidetracked) whether there was a way to have Maven also generate
    SHA256, SHA512, etc hashes during a 'deploy', instead of or in
    addition to the MD5 and SHA1 ones.<br class=""></div></div></blockquote><div><br class=""></div><div>SHA-1 and even MD5 are fine as *integrity* checks. I don't see a need to go to even SHA-256 for that purpose.</div><div><br class=""></div><div>Providing longer hashes doesn't give you more in the way of *authenticity* unless you're actually performing signatures.</div><div><br class=""></div><div>In practice, of course, there's the "optics" of it, as Scott would say: if someone doesn't understand that distinction, giving them a SHA-256 or even SHA-512 hash as well may make them feel better, even if it really shouldn't, and the reduced support load might be of value.</div></div><div class="">
<span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px;"><div class=""><span class="Apple-tab-span" style="white-space: pre;"><br class="Apple-interchange-newline"></span>&nbsp; &nbsp; -- Ian<br class=""></div><div class=""><span class="Apple-style-span" style="font-size: medium;"><br class=""></span></div></span></div></span><br class="Apple-interchange-newline"><br class="Apple-interchange-newline">
</div>
<br class=""></body></html>