Skip to content

Vendored JVM fetches upstream artifacts and checksums only from Maven Central, ignoring the build's mirrors and repositories #1069

Description

[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.

Kind: bug. Source: audit B63 (new finding), register E86.

Problem: maven_registry_base() returns SOCKET_MAVEN_REGISTRY or Maven Central, and it is the only remote base for acquire_classifier, verify_jvm_upstream, acquire_jvm_artifact, acquire_upstream_pom and agent-mode jvm_jar.rs. settings.xml <mirrors>, pom <repositories>, Gradle repositories {} and sbt resolvers are never read. An online vendor always fetches .sha512/.sha1 from that base, even when the bytes came from a local cache, and refuses with vendor_jvm_upstream_unavailable on any fetch error.

Impact: on a network that reaches Central only through a corporate mirror, every online JVM vendor fails closed; the process-global env var is the only workaround. No silent unpatched build. Low priority per the maintainer's ecosystem triage.

Proposed change: resolve the upstream base per build (the effective settings.xml mirror for central, the Gradle repositories, or the sbt/Coursier resolution URL already in the gate evidence) and fall back to Central with a named warning. Land it in vendor::jvm::layout::registry_base (#1032).

Acceptance criteria:

  • A Maven project with a mirrorOf central mirror vendors online against the mirror.
  • A warning names the fallback when no build repository is usable.

Dependencies: after #1032. Related: E43, #263.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)bugSomething isn't workingpm:mavenMavenpriority:p3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions