<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div class="">Hi,</div><div class=""><br class=""></div><div class="">I work on an open source project [0] with Apache Sling [1] that uses the OpenSAML </div><div class="">v4 library. The pre-release includes the Shibboleth repository [2] in the pom.xml</div><div class=""><br class=""></div><div class="">We are near the point in the project where this project may be released to Maven Central </div><div class="">as is common practice for all Apache Software Foundation Java artifacts.</div><div class=""><br class=""></div><div class="">Central has the following guidance regarding 3rd party artifacts [3]</div><blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;" class=""><div class="">we discourage the usage of <repositories> and <pluginRepositories> and instead </div><div class="">publish any required components to the Central Repository. </div><div class="">This applies for your own components as well as for 3rd party artifacts.</div></blockquote><div class=""><div class=""><br class=""></div><div class="">But I have also read the Shibboleth wiki about Maven Central [4]</div><div class="">So there is tension between these two recommendations.</div><div class=""><br class=""></div><div class="">My PMC questions whether the Shibboleth repository is needed for our project,  </div><div class="">because v4.0.1 is available from Central.  It came as a bit of surprise, so I’m suspicious </div><div class="">about the veracity of the OpenSAML artifacts from Central, given the aforementioned </div><div class="">wiki post.</div><div class=""><br class=""></div><div class=""><blockquote style="margin: 0px 0px 0px 40px; border: none; padding: 0px;" class=""><div class="">As an example, the OpenSAML artifacts currently uploaded to Maven Central are not </div><div class="">provided by the Shibboleth project nor are they artifacts that we've released (i.e., </div><div class="">the jars out there have been changed in some unknown way).</div><div class=""><br class=""></div></blockquote></div><div class=""><br class=""></div><div class="">I have started calculating the sha1 hashes for the artifacts as obtained from Maven </div><div class="">Central and comparing to the hashes published to the Shibboleth repo [6]. </div><div class="">So far, they indicate the artifacts contents are indeed the same. </div><div class="">I may continue verifying the artifact's integrity.</div><div class=""><br class=""></div><div class="">Please let me know...</div><div class=""><br class=""></div></div><div class=""><div class="">Has anything changed with respect to publishing artifacts to Maven Central as compared to the wiki?</div><div class=""><br class=""></div><div class="">Do you have any knowledge about how OpenSAML v4.0.1 artifacts were uploaded to Central in Feb 2021? </div><div class=""><br class=""></div><div class="">Is it still presumed these were modified in some way as the wiki suggests?</div></div><div class=""><br class=""></div><div class="">Please let me know if you have any other suggestions.</div><div class=""><div class=""><br class=""></div><div class="">
Best regards,</div><div class=""><span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); font-family: Verdana; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;" class="">Cris R</span></div><div class=""><br class=""></div><div class=""><span style="text-align: start; text-indent: 0px; float: none; display: inline !important;" class=""><br class="">[0] </span><a href="https://github.com/apache/sling-org-apache-sling-auth-saml2" class="">https://github.com/apache/sling-org-apache-sling-auth-saml2</a></div><div class=""><span style="text-align: start; text-indent: 0px; float: none; display: inline !important;" class="">[1] <a href="https://sling.apache.org/" class="">https://sling.apache.org/</a><br class="">[2] </span><a href="https://github.com/apache/sling-org-apache-sling-auth-saml2/blob/c3442267abeffad22e411fb1149cb8f80ef9361a/pom.xml#L404-L413" class="">https://github.com/apache/sling-org-apache-sling-auth-saml2/blob/c3442267abeffad22e411fb1149cb8f80ef9361a/pom.xml#L404-L413</a> </div><div class=""><span style="text-align: start; text-indent: 0px; float: none; display: inline !important;" class="">[3] </span><a href="https://central.sonatype.org/publish/requirements/" class="">https://central.sonatype.org/publish/requirements/</a></div><div class=""><span style="text-align: start; text-indent: 0px; float: none; display: inline !important;" class="">[4] <a href="https://wiki.shibboleth.net/confluence/display/DEV/Use+of+Maven+Central" class="">https://wiki.shibboleth.net/confluence/display/DEV/Use+of+Maven+Central</a><br class="">[5] <a href="https://mvnrepository.com/artifact/org.opensaml/opensaml-core/4.0.1" class="">https://mvnrepository.com/artifact/org.opensaml/opensaml-core/4.0.1</a></span></div><div class=""><span style="text-align: start; text-indent: 0px; float: none; display: inline !important;" class="">[6] <a href="https://build.shibboleth.net/nexus/content/groups/public/org/opensaml/opensaml-core/4.0.1/opensaml-core-4.0.1.jar.sha1" class="">https://build.shibboleth.net/nexus/content/groups/public/org/opensaml/opensaml-core/4.0.1/opensaml-core-4.0.1.jar.sha1</a></span></div>
<br class=""></div></body></html>