tools-deps 2024-11-07

In Leiningen I can ignore checksums of transitive dependencies of git repositories as follows:

:repositories [["private-bitbucket" {:url ""
                                     :protocol :ssh
                                     :checksum :ignore}]]
can something similar be done for the git dependencies in deps.edn? To prevent the error: > Could not transfer artifact mediquest-nl:mq-ui:jar:82004cd5579313a6f470883d7f46d8ce5d4f5c16 from/to private-bitbucket (): Checksum validation failed, no checksums available Or is this a case of “the advantage of security is security and the disadvantage of security is security”? And if so, how can I get git dependencies with their own deps.edn file to work?

Thanks. I’ve seen that documentation, but it’s unclear what I need to add in my specific case. This is also about mvn repositories and not git ones?

Alex Miller (Clojure team) 2024-11-07T15:29:27.600429Z

Oh, I don’t understand what checksums have to do with git repos?

Well I suspect there are transitive dependencies, but maybe I’m wrong

Alex Miller (Clojure team) 2024-11-07T15:30:19.230099Z

I don’t understand what you’re doing if you can back up to explain

It should just work, but the fact of the matter is I get a checksum error. A similar error I got in Leiningen and I could solve it by ignoring checksums for the git repository.

Alex Miller (Clojure team) 2024-11-07T15:31:33.223289Z

Is this a maven repo stored in git accessed via ssh?

Alex Miller (Clojure team) 2024-11-07T15:32:51.715719Z

If so, I’ve never tried that and I would be surprised if it worked, particularly the protocol bit

In deps.edn we basically have a dependency like this:

nl.mediquest/mq-lib {:git/sha "COMMIT_HASH"
                     :git/url "git@bitbucket.org:mediquest-nl/mq-lib.git"}
this used to work, but now we get the checksum error. The repository is basically code shared between repos. But, I did add a pom.xml recently, maybe that messes things up.

Alex Miller (Clojure team) 2024-11-07T15:34:36.162109Z

Is the error up at the top from using clj or lein?

from clj

at least the project is using clj

Alex Miller (Clojure team) 2024-11-07T15:35:36.133699Z

If you are using a git dep, there is no jar or checksum to check so I don’t understand the error

hmm okay me neither 😉

i can try removing the pom.xml

Alex Miller (Clojure team) 2024-11-07T15:37:29.874209Z

Do you have custom repos in your deps.edn?

Alex Miller (Clojure team) 2024-11-07T15:41:28.794409Z

The combination of things you’ve told me do not make sense together so I am missing something. Using a git dep will checkout the git repo locally in your gitlibs. No jar is downloaded. The error at top shows an error transferring a jar from a custom maven repo. That has to be set up somewhere if it’s not in your project deps, probably in your ~/.clojure/deps.edn

Alex Miller (Clojure team) 2024-11-07T15:42:08.264269Z

Wherever that is, you can use the maven repo config I referred to to turn off checksum validation

The error comes from a pipeline, so no ~/.clojure/deps.edn there I think

As a last resort I will disable all checksum validation

thanks for the help!

Alex Miller (Clojure team) 2024-11-07T15:43:21.029899Z

The repo in the error message is defined somewhere

removal of the pom.xml doesn’t make a difference logicaly, but that’s not it

You are right Alex, the error is actually not coming from the deps.edn project facepalm

Alex Miller (Clojure team) 2024-11-07T15:46:18.549259Z

:)

it’s a separate pipeline for the frontend that uses Leiningen and has that repository defined

I looked crookedly and thought the error was from the backend deps.edn project

well now I know how to fix it 🙂 thanks for clarifying it could not be deps.edn 🙂

otherwise might have kept overlooking