Re: RFC: Maven to raise a notification if downloading vulnerable content

2018-03-06 Thread Peter Muryshkin
the package repository to add the header, you will need to > make your request to Sonatype (Nexus) and JFrog (Artifactory) > > Chas > > > On Mar 6, 2018, at 4:12 AM, Peter Muryshkin <murysh...@gmail.com> wrote: > > > > Hi, all, > > > > currently you

RFC: Maven to raise a notification if downloading vulnerable content

2018-03-06 Thread Peter Muryshkin
Hi, all, currently you can run OWASP dependency check plugin against your projects. Though, this seems to make security more or less optional: unaware either lightheaded teams could miss this. What if a package repository would integrate with this dependency checking and issue a warning, say a