Skip to content

Unexpected version release lifecycle and provider (20250107.0.0.redhat-00001) #977

@ron190

Description

@ron190

Hi,

Artifact like 20250107.0.0.redhat-00001 have been released recently, and following this release dependabot has also created an automatic PR.

Here's an example of those redhat versions pushed by dependabot for several groupId:artifactId : https://github.com/ron190/jsql-injection/pulls?q=is%3Apr+is%3Aopen+redhat

We can see those json artifacts also on mavenrepo: https://mvnrepository.com/artifact/org.json/json?repo=redhat-ga

As we are hearing about supply chain issues since some times :

  • Should we care for any version released other than the version coming from Central provider ?

  • Do you know these dozen other providers origins ? are there any legitimacy consideration to have regarding those other providers ?

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions