How is maven different than ruby gems?

http://venturebeat.com/2013/01/30/rubygems-org-hacked-interrupting-heroku-services-and-putting-millions-of-sites-using-rails-at-risk/

-- 
Travis Wellman <[email protected]>
http://traviswellman.com/

On Thu, 31 Jan 2013 10:36:09 -0600
Ian Clarke <[email protected]> wrote:

> I recall that the reason for not using Maven is that it doesn't operate
> over a secure connection, and it leaves us open to the compromise of any of
> Freenet's dependencies Maven repositories.
> 
> This is despite the fact that no such compromise as ever occurred on any
> project that I'm aware of, and since we don't do code audits of Freenet's
> current dependencies, our current approach doesn't immunize us against it
> anyway.
_______________________________________________
Devl mailing list
[email protected]
https://emu.freenetproject.org/cgi-bin/mailman/listinfo/devl

Reply via email to