Dan, It is a policy matter, not a legal one. And enforcing artifact signing would address this and other crucial, fatal, flaws in Maven's repository management.
I still maintain that unless Maven makes swift strides to enforce signing, the ASF should ban the use of the Maven repository for all ASF projects, and go so far as to remove all of our artifacts. --- Noel --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]