Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One further note... The version of Sonatype Nexus that Maven Central is running does not support signing with a subkey, and does not support ECDSA. Unfortunately, the software that needs to be fixed is proprietary.

If someone has a contact at Sonatype, I'd love to talk to them about fixing this.



The source code is at https://github.com/sonatype/nexus-public.

Not sure if Maven Central is running on the closed-source version, though.

> If someone has a contact at Sonatype, I'd love to talk to them about fixing this.

Contact them by email, they're quite responsive.


Thanks. I checked the code out but it does looks like that part is not open source :( I'll email them




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: