ChestShop - the chest & sign shop plugin for Minecraft Servers running Bukkit/Spigot/Paper
Go to file
Jonathan Leitschuh 5066a21a5f
vuln-fix: Use HTTPS instead of HTTP to resolve deps CVE-2021-26291
This fixes a security vulnerability in this project where the `pom.xml`
files were configuring Maven to resolve dependencies over HTTP instead of
HTTPS.

Weakness: CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Severity: High
CVSSS: 8.1
Detection: CodeQL & OpenRewrite (https://public.moderne.io/recipes/org.openrewrite.maven.security.UseHttpsForRepositories)

Reported-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>

Bug-tracker: https://github.com/JLLeitschuh/security-research/issues/8

Co-authored-by: Moderne <team@moderne.io>
2022-07-14 22:41:37 +00:00
.github Improve agreements 2021-10-15 01:15:52 +01:00
repo Remove OddItem support and implement own alias system (Resolves #360) 2021-01-03 01:55:01 +01:00
src Build against 1.19 and replace apache-commons-lang 2022-06-13 22:52:26 +01:00
.crowdin.yml New Crowdin updates (#375) 2020-12-07 18:13:04 +01:00
.gitignore Modify gitignore 2013-08-09 00:08:08 +02:00
LICENSE Add missing LGPLv2.1 license 2017-07-04 15:23:15 +01:00
README.md Add crowdin setup 2020-10-31 21:56:35 +01:00
SECURITY.md Just use latest instead of specific version 2021-02-19 13:38:35 +01:00
install_dependency_to_repo.sh CRLF -> LF 2014-06-29 16:40:49 +02:00
pom.xml vuln-fix: Use HTTPS instead of HTTP to resolve deps CVE-2021-26291 2022-07-14 22:41:37 +00:00

README.md

ChestShop

Development downloads can be found here: https://ci.minebench.de/job/ChestShop-3/

ChestShop is an awesome plugin for managing your server's economy. By using chests and signs, you can effectively create your own market!

ChestShop also makes admininstators' lives easier. Simply drag-and-drop the .jar to your "plugins" folder and you're done!

If you need any help - just ask. There is a ticket system, in which you can report bugs, suggest improvements and more. Don't be fooled though - you might think that your ticket disappeared, however that's not the case.
You should configure the system to show "All tickets", instead of only "All open" - you can do that by clicking on the "Filters".

Building

Installing

To build ChestShop, you'll need a Maven installation.

Installing external dependencies

To install external dependencies, place your .jar into the main folder and launch the install_dependency_to_repo.sh script - it'll guide you through the process.