Repository navigation
distributionSha256Sum property gets removed when upgrading/reinstalling #367
Description
Activity
- changed the title
[-]`distributionSha256Sum` property gets removed when upgrading to Maven Wrapper 3.3.3[/-][+]`distributionSha256Sum` property gets removed when upgrading/reinstalling[/+]on Sep 4, 2025 Hello, I am a beginner contributor and I am learning the Maven Wrapper codebase.
I would like to explore this issue and start with understanding why distributionSha256Sum is removed during reinstall. Please let me know if that’s okay.Ok with me, but I'm just the reporter of this issue.
Thanks for the clarification. I’ll start by investigating the current behavior and share my findings here.
I’m currently exploring the maven-wrapper-plugin module to understand how maven-wrapper.properties is generated during wrapper upgrade/reinstall. I’m tracing where the properties file is written to see why existing values like distributionSha256Sum are not preserved.
I investigated the issue in maven-wrapper-plugin, specifically in WrapperMojo#replaceProperties.
During wrapper reinstall/upgrade, the method always rewrites maven-wrapper.properties and does not load existing properties first, so previously configured values like distributionSha256Sum are lost unless explicitly passed again via CLI.A possible improvement could be loading existing maven-wrapper.properties (if present) and preserving user-defined properties when reinstalling with the same Maven distribution.
Would you prefer preserving all existing properties or only specific ones like distributionSha256Sum?
As a user I think it would make sense that only properties set by the setup process get overwritten, and all others stay as-is, but I don't know what the Maven maintainers think is the correct/best behavior.
I agree, that approach sounds reasonable to me as well.
From what I saw in WrapperMojo#replaceProperties, the current behavior always rewrites the file.
Preserving existing user-defined properties while overwriting only setup-controlled ones (unless explicitly overridden) seems like a good balance, but I’ll wait for the maintainers’ guidance on the preferred behavior.If you're looking for guidance from maintainers, you may need to actively ask for that on the mailing list, because they might not see the conversation in this issue.
Affected version
3.3.3
Bug description
When I upgrade/reinstall Maven Wrapper, the
distributionSha256Sumproperty gets removed from.mvn/wrapper/maven-wrapper.properties.To reproduce (using Maven 3.9.11 as
mvn):I think the
distributionSha256Sumshould be retained when the Maven Wrapper version is changed (or the same version is reinstalled).An open question is what should happen when the update command changes the Maven distribution (e.g.
-Dmaven=3.9.10), because in that scenario retainingdistributionSha256Sumwith the existing value will cause Maven Wrapper to fail.Could Maven Wrapper at least warn that the user should set
distributionSha256Sumagain for the new Maven version to not lose the integrity check protection? Or could the value even be updated automatically in a safe way? If so, it should probably also be set by default during an initial Maven Wrapper setup.