Skip to content

docs: rewrite about-checksums.md to STE rules - #2024

Merged
elharo merged 9 commits into
masterfrom
update-about-checksums-ste
Aug 4, 2026
Merged

elharo merged 9 commits into
masterfrom
update-about-checksums-ste

Conversation

@elharo

@elharo elharo commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@elharo elharo added the documentation Improvements or additions to documentation label Aug 3, 2026
@elharo
elharo marked this pull request as ready for review August 4, 2026 11:27
@elharo
elharo requested a review from gnodet August 4, 2026 11:27

@gnodet gnodet left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice STE rewrite — shorter sentences and active voice improve readability, and all hyperlinks are preserved this time (good!). A couple of accuracy items and some minor polish suggestions below.

This review was generated by an AI agent (Claude Code) and may contain inaccuracies. Please verify all suggestions before applying.

On behalf of gnodet

Comment thread src/site/markdown/about-checksums.md Outdated
proliferation of non-standard checksums.

## Implemented Checksum Algorithms
The user configuration enables POMs to specify arbitrary checksum algorithms,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The original was deliberately generic ("one can set them via configuration"). The rewrite introduces "POMs" as the mechanism, but the project's own expected-checksums.md docs show checksum algorithms are configured via system properties (aether.layout.maven2.checksumAlgorithms) and -D flags, not POMs.

Suggested change
The user configuration enables POMs to specify arbitrary checksum algorithms,
Configuration allows users to specify arbitrary checksum algorithms,
even if they are not part of the standard Maven process.


In the past, Maven Resolver used `java.security.MessageDigest` to calculate checksums.
The Java Cryptography Architecture provides secure one-way hashes.
Maven Resolver used these secure hashes to verify transport integrity.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The original's "(mis)used" was intentional editorial commentary — it acknowledged that applying cryptographic hash functions as transport checksums was a design shortcut, which motivates the SPI section that follows. Dropping it entirely loses that context. Consider preserving the nuance, e.g.:

Maven Resolver repurposed these secure hashes as checksums for transport integrity validation.

Comment thread src/site/markdown/about-checksums.md Outdated
This fact is true for the SHA-1 algorithm and the MD5 algorithm.
Industry still uses both algorithms today to verify transport integrity and to detect errors.

To prove that artifacts have not been tampered with, you need signatures such as

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor: "prove" is stronger than the original "trust." GPG signatures provide cryptographic assurance from a trusted signer — they establish trust, not mathematical proof. The original word was more precise.

Suggested change
To prove that artifacts have not been tampered with, you need signatures such as
To trust that artifacts have not been tampered with, you need signatures such as

Co-authored-by: Guillaume Nodet <gnodet@gmail.com>

@gnodet gnodet left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing the grammar (comma + antecedent)! The main remaining item is the "POMs" reference on line 38 — checksum algorithms in Maven Resolver are configured via system properties (e.g. aether.checksums.algorithms), not POMs. The original was generic ("one can set them via configuration") for good reason. The previous review's suggestion block for this line is still applicable.

The other items ("(mis)used" context, "prove" vs. "trust") are editorial — your call whether to adjust.

This review was generated by an AI agent (Claude Code) and may contain inaccuracies. Please verify all suggestions before applying.

On behalf of gnodet

@gnodet gnodet left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The "POMs" reference is correctly replaced with "System properties" — factually accurate now. Grammar fix and this fix together address the substantive items. LGTM!

This review was generated by an AI agent (Claude Code) and may contain inaccuracies. Please verify all suggestions before applying.

On behalf of gnodet

* docs: rewrite api-compatibility.md to STE rules
* docs: clarify clients vs extensions terminology



Co-authored-by: Guillaume Nodet <gnodet@gmail.com>

* Update src/site/markdown/api-compatibility.md

Co-authored-by: Guillaume Nodet <gnodet@gmail.com>

---------

Co-authored-by: Guillaume Nodet <gnodet@gmail.com>
@elharo
elharo merged commit 26f40ee into master Aug 4, 2026
23 checks passed
@elharo
elharo deleted the update-about-checksums-ste branch August 4, 2026 18:12
@github-actions github-actions Bot added this to the 2.0.22 milestone Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants