<p></p>
<blockquote>
<p>Especially when <code>gradle/witness/gradle-witness.gradle</code> only store SHA1 vulnerable to pre-image attack</p>
</blockquote>
<p>It's actually SHA-256 (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="843400393" data-permission-text="Title is private" data-url="https://github.com/bisq-network/bisq/issues/5372" data-hovercard-type="pull_request" data-hovercard-url="/bisq-network/bisq/pull/5372/hovercard" href="https://github.com/bisq-network/bisq/pull/5372">#5372</a>).</p>
<blockquote>
<p>it would be a good thing for packager to be able to download all the needed archives using their own respective process and let gradle use a local predefined directory to pick each pom/jar so the build can be made in a network restrict sandbox</p>
</blockquote>
<p>Something like that might be possible using this approach: <a href="https://stackoverflow.com/questions/7016226/how-to-configure-gradle-to-use-a-local-repository-only-for-certain-dependency-gr" rel="nofollow">https://stackoverflow.com/questions/7016226/how-to-configure-gradle-to-use-a-local-repository-only-for-certain-dependency-gr</a></p>
<p>However this is a very esoteric sort of setup with its own set of challenges. It might be worth enabling network access for the build process, or just building on a separate dedicated VM, if necessary.</p>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">—<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/bisq-network/bisq/issues/4730#issuecomment-809406910">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/AJFFTNXR2PUW3SU24KFWHWTTGCJYZANCNFSM4TETZQVA">unsubscribe</a>.<img src="https://github.com/notifications/beacon/AJFFTNTV5B3PWODGHSMIUCLTGCJYZA5CNFSM4TETZQVKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOGA7JDPQ.gif" height="1" width="1" alt="" /></p>
<script type="application/ld+json">[
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"potentialAction": {
"@type": "ViewAction",
"target": "https://github.com/bisq-network/bisq/issues/4730#issuecomment-809406910",
"url": "https://github.com/bisq-network/bisq/issues/4730#issuecomment-809406910",
"name": "View Issue"
},
"description": "View this Issue on GitHub",
"publisher": {
"@type": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]</script>