Skip to content

Difference between integration test jar-signing and jar-signing-extra #2094

Answered by laeubi
lppedd asked this question in Q&A
Discussion options

You must be logged in to vote

Am I right?

Yes, also keep in mind that with first, you only sign items you currently build, while the second will also sign items you consume from elsewhere, especially with code-signing I won't recommend this, unless you really carefully have investigated your dependency chain, as all code signed with run under your name and your granted access rights!

And which approach would you pick today?

This depends on so many aspects that there is no generic answer (see above) if code signing is not only your vehicle for "I don't want to get a warning at install" ...

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@lppedd
Comment options

@laeubi
Comment options

Answer selected by lppedd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants