Skip to content

add blog about maven artifact resolution - #384

Open
sebtiem wants to merge 5 commits into
mainfrom
blog-maven-artifacts
Open

add blog about maven artifact resolution#384
sebtiem wants to merge 5 commits into
mainfrom
blog-maven-artifacts

Conversation

@sebtiem

@sebtiem sebtiem commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

@netlify

netlify Bot commented Aug 11, 2026

Copy link
Copy Markdown

Deploy Preview for open-elements ready!

Name Link
🔨 Latest commit 8695b0b
🔍 Latest deploy log https://app.netlify.com/projects/open-elements/deploys/6a99670e4baf7900085f04f1
😎 Deploy Preview https://deploy-preview-384--open-elements.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 73
Accessibility: 98
Best Practices: 92
SEO: 100
PWA: 60
View the detailed breakdown and full score reports

To edit notification comments on pull requests, go to your Netlify project configuration.

Comment thread content/posts/2026-08-xx-maven-artefakt-herkunft.md Outdated
Comment thread content/posts/2026-08-xx-maven-artefakt-herkunft.md Outdated
Comment thread content/posts/2026-08-xx-maven-artefakt-herkunft.md Outdated
Comment thread content/posts/2026-08-xx-maven-artefakt-herkunft.md Outdated
Comment thread content/posts/2026-08-xx-maven-artefakt-herkunft.md Outdated
Comment thread content/posts/2026-08-xx-maven-artefakt-herkunft.md Outdated
@sebtiem sebtiem changed the title Draft: add blog about maven artifact resolution add blog about maven artifact resolution Sep 3, 2026
---


# Woher kommt dieses Artefakt eigentlich? Vom Maven Repository und der Datei `_remote.repositories`

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wenn du https://deploy-preview-384--open-elements.netlify.app/de/posts/2026/08/12/von-der-supply-chain-lokal-gebauten-artefakten-und-wie-maven-damit-umgeht aufruft siehts du dass es 2 Headlines direkt untereinander gibt, da du ja die Headline des blocks bereits hast. Daher macht die zweite direkte Headline wenig Sinn.

Dazu: Was ist "dieses Artefakt"??? Welches


# Woher kommt dieses Artefakt eigentlich? Vom Maven Repository und der Datei `_remote.repositories`

Reproducible Builds beruhen auf einer einfachen Zusage: derselbe Quellcode, dieselbe Build-Umgebung, dasselbe Ergebnis,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hier link zu Reproducible Builds zu irgendeiner Seite die er erläutert.

Referenz. Wenn beide übereinstimmen, ist gezeigt, dass die veröffentlichten Artefakte tatsächlich aus dem angegebenen
Quellcode entstanden sein können.

Ein Vergleich ist allerdings nur so gut wie sein Vergleichsmaßstab. Wenn eine der beteiligten Abhängigkeiten nicht aus

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Vergleichsmaßstab finde ich komisch. Musste weiterlesen um zu verstehen was du damit meinst

gebaut worden sind, dann vergleicht man am Ende ein lokales Ergebnis mit einem anderen lokalen Ergebnis. Das Resultat
sieht sauber aus, es sagt aber nichts über die veröffentlichten Artefakte aus. Aus Supply-Chain-Perspektive ist ein
lokal installiertes Artefakt ein Input in den Build, der von niemandem geprüft wurde, weder durch eine Signatur noch
durch eine Checksumme gegen ein Remote-Repository. Wie sich in der Vergangenheit gezeigt hat, könnte hier bereits

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

der Vergangenheit gezeigt <- Gibt es da nen Beleg als Link?


## Wie Maven das lokale Repository verwaltet

Unterhalb von Maven arbeitet der Maven Artifact Resolver, das frühere Aether. Es kapselt alles, was mit Repositories

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

das frühere Aether <- würde ich rausnehmen. Wird niemand der das liest was sagen

Datei nicht heruntergeladen, sondern lokal installiert wurde. Fehlt zu einer vorhandenen Datei jeglicher Eintrag,
dann gilt sie intern ebenfalls als lokal installiert.

Diese Datei ist damit essentiell für die Basis für die Lösung von MARTIFACT-58.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

" des Tickets". Niemand wird mehr wissen was MARTIFACT-58 ist

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants