Skip to content

distributionSha256Sum property gets removed when upgrading/reinstalling #367

Description

@breun

Affected version

3.3.3

Bug description

When I upgrade/reinstall Maven Wrapper, the distributionSha256Sum property gets removed from .mvn/wrapper/maven-wrapper.properties.

To reproduce (using Maven 3.9.11 as mvn):

mkdir reproducer
cd reproducer

# Install Maven Wrapper 3.3.3
mvn wrapper:3.3.3:wrapper -Dmaven=3.9.11

# Set distributionSha256Sum to verify integrity of Maven distribution
echo "distributionSha256Sum=0d7125e8c91097b36edb990ea5934e6c68b4440eef4ea96510a0f6815e7eeadb" >> .mvn/wrapper/maven-wrapper.properties

# Install Maven Wrapper 3.3.3 again (no newer version available yet at this time)
./mvnw wrapper:3.3.3:wrapper

# This returns nothing, because distributionSha256Sum has been removed during the upgrade
grep distributionSha256Sum .mvn/wrapper/maven-wrapper.properties

I think the distributionSha256Sum should be retained when the Maven Wrapper version is changed (or the same version is reinstalled).

An open question is what should happen when the update command changes the Maven distribution (e.g. -Dmaven=3.9.10), because in that scenario retaining distributionSha256Sum with the existing value will cause Maven Wrapper to fail.

Could Maven Wrapper at least warn that the user should set distributionSha256Sum again for the new Maven version to not lose the integrity check protection? Or could the value even be updated automatically in a safe way? If so, it should probably also be set by default during an initial Maven Wrapper setup.

Activity

  1. added
    bugSomething isn't working
    on Sep 4, 2025
  2. changed the title [-]`distributionSha256Sum` property gets removed when upgrading to Maven Wrapper 3.3.3[/-] [+]`distributionSha256Sum` property gets removed when upgrading/reinstalling[/+] on Sep 4, 2025
  3. Harsha-Deep-Yenneboina commented on Jan 31, 2026

    @Harsha-Deep-Yenneboina

    Hello, I am a beginner contributor and I am learning the Maven Wrapper codebase.
    I would like to explore this issue and start with understanding why distributionSha256Sum is removed during reinstall. Please let me know if that’s okay.

  4. breun commented on Jan 31, 2026

    @breun
    ContributorAuthor

    Ok with me, but I'm just the reporter of this issue.

  5. Harsha-Deep-Yenneboina commented on Feb 1, 2026

    @Harsha-Deep-Yenneboina

    Thanks for the clarification. I’ll start by investigating the current behavior and share my findings here.

  6. Harsha-Deep-Yenneboina commented on Feb 1, 2026

    @Harsha-Deep-Yenneboina

    I’m currently exploring the maven-wrapper-plugin module to understand how maven-wrapper.properties is generated during wrapper upgrade/reinstall. I’m tracing where the properties file is written to see why existing values like distributionSha256Sum are not preserved.

  7. Harsha-Deep-Yenneboina commented on Feb 1, 2026

    @Harsha-Deep-Yenneboina

    I investigated the issue in maven-wrapper-plugin, specifically in WrapperMojo#replaceProperties.
    During wrapper reinstall/upgrade, the method always rewrites maven-wrapper.properties and does not load existing properties first, so previously configured values like distributionSha256Sum are lost unless explicitly passed again via CLI.

  8. Harsha-Deep-Yenneboina commented on Feb 1, 2026

    @Harsha-Deep-Yenneboina

    A possible improvement could be loading existing maven-wrapper.properties (if present) and preserving user-defined properties when reinstalling with the same Maven distribution.

  9. Harsha-Deep-Yenneboina commented on Feb 1, 2026

    @Harsha-Deep-Yenneboina

    Would you prefer preserving all existing properties or only specific ones like distributionSha256Sum?

  10. breun commented on Feb 1, 2026

    @breun
    ContributorAuthor

    As a user I think it would make sense that only properties set by the setup process get overwritten, and all others stay as-is, but I don't know what the Maven maintainers think is the correct/best behavior.

  11. Harsha-Deep-Yenneboina commented on Feb 5, 2026

    @Harsha-Deep-Yenneboina

    I agree, that approach sounds reasonable to me as well.
    From what I saw in WrapperMojo#replaceProperties, the current behavior always rewrites the file.
    Preserving existing user-defined properties while overwriting only setup-controlled ones (unless explicitly overridden) seems like a good balance, but I’ll wait for the maintainers’ guidance on the preferred behavior.

  12. breun commented on Feb 6, 2026

    @breun
    ContributorAuthor

    If you're looking for guidance from maintainers, you may need to actively ask for that on the mailing list, because they might not see the conversation in this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions