Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Maven has this problem

What malicious packages have been found on Maven central?



Why don't you google or follow the link I already gave?


Exactly what I thought. You can't name one. Coincidentally, Maven central requires GPG signatures.


As we all know you can only sign a piece of code if it is free of malicious software.

Heck, I read that you can't even make a GPG key without proving your virtue to Richard Stallman in festivus-style competition.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: