OWASP / java-html-sanitizer

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.
Other
854 stars 214 forks source link

Error adding depency in sbt from Maven Central (insecure dependencies via http) #191

Closed phwiget closed 4 years ago

phwiget commented 4 years ago

Because of the new security policy on maven central it is currently not possible to include the library as dependency. The reason are some depencendies via http instead of https which is now enforced by maven central.

Currently I would like to include the library (or: had included already, now clean builds don't work anymore) via sbt. Here are the affected dependencies:

[error] SERVER ERROR: HTTPS Required url=http://repo1.maven.org/maven2/com/google/code/findbugs/jsr305/
[error] SERVER ERROR: HTTPS Required url=http://repo1.maven.org/maven2/com/google/code/findbugs/jsr305/
[warn]  module not found: com.google.code.findbugs#jsr305;[2.0.1,)
[warn] ==== local: tried
[warn]   C:\Users\user\.ivy2\local\com.google.code.findbugs\jsr305\[revision]\ivys\ivy.xml
[warn] ==== activator-local: tried
[warn]   file:/C:/Users/user/Scala/logo/repository/com.google.code.findbugs/jsr305/[revision]/ivys/ivy.xml
[warn] ==== public: tried
[warn]   http://repo1.maven.org/maven2/com/google/code/findbugs/jsr305/[revision]/jsr305-[revision].pom
[warn] ==== typesafe-releases: tried
[warn]   http://repo.typesafe.com/typesafe/releases/com/google/code/findbugs/jsr305/[revision]/jsr305-[revision].pom
[warn] ==== typesafe-ivy-releasez: tried
[warn]   http://repo.typesafe.com/typesafe/ivy-releases/com.google.code.findbugs/jsr305/[revision]/ivys/ivy.xml
[warn] ==== Typesafe Releases Repository: tried
[warn]   https://repo.typesafe.com/typesafe/releases/com/google/code/findbugs/jsr305/[revision]/jsr305-[revision].pom
phwiget commented 4 years ago

Was because I had an old sbt version...

mikesamuel commented 4 years ago

Glad you figured it out. Thanks for closing.

Dhoot commented 4 years ago

@phwiget I am having play v2.1.5 which sbt shall I switch to ?

phwiget commented 4 years ago

I installed version >= 1.0