Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
brianefox
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
brianefox
12y ago
Fwiw, Bintray requires the private key and passphrase to do the signing. This isn't really proper key handling and has been pointed out before.
2.
▲
by
brianefox
12y ago
As a representative of Sonatype. The reality of cross build injection has been discussed for many years, I even linked to an XBI talk in my blog post announcing the availability of SSL. The reality is that prior to moving to a CDN, it was g
3.
▲
by
brianefox
12y ago
Signatures have been required on Central for years and there are tools to verify them, including repository managers. We strongly do not believe that you should entrust your private key to anyone else for signing, which is what others have
4.
▲
by
brianefox
12y ago
The project to offer ssl free to every user of Maven Central is already underway. Stay tuned for details.