In this case, it’s safe to run the If the checksum is not listed on the page, the Wrapper JAR might be from a milestone, release candidate, or nightly build — or it might indeed not be legitimate.You should try to find out how it was generated but treat it as untrustworthy until proven otherwise.All Wrapper files including the JAR file are very small in size.Adding the JAR file to version control is expected.As with all such files, you should be sure that it’s trustworthy before executing it.For example, since the Wrapper JAR is usually checked into a project’s version control system, there is the potential for a malicious actor to replace the original JAR with a modified one by committing it or submitting a pull request that seemingly only upgrades the Gradle version.

The Wrapper is a script that invokes a declared version of Gradle, downloading it beforehand if necessary.Checksum Verification is only performed if the configured Wrapper distribution hasn’t been downloaded yet.The Wrapper JAR is a binary file that will be executed on the computers of developers and build servers.Depending on the operating system you either run $ build Downloading C:\Documents and Settings\Claudia\.gradle\wrapper\dists\gradle-5.0-all\ac27o8rbd0ic8ih41or9l32mv\gradle-5.0to C:\Documents and Settings\Claudia\.gradle\wrapper\dists\gradle-5.0-al\ac27o8rbd0ic8ih41or9l32mv Set executable permissions for: C:\Documents and Settings\Claudia\.gradle\wrapper\dists\gradle-5.0-all\ac27o8rbd0ic8ih41or9l32mv\gradle-5.0\bin\gradle BUILD SUCCESSFUL in 12s 1 actionable task: 1 executed In case the Gradle distribution is not available on the machine, the Wrapper will download it and store in the local file system.

