On Sun, 2004-07-11 at 11:00, Stepan Koltsov wrote:
> Hi,
> 
> So I can create, for example, hibernate-2.1.4-bundle.jar and put it
> somewhere (say at my homepage)? But who checks if bundle I've created
> contains real hibernate library and does not contain hack that does
> "rm -rf /" ? Hibernate is very popular library, and damage from
> faking it may be very big...

What has been happening over time is that for prominent OSS projects I
have organized syncs to ibiblio making the projects accountable for what
is placed in the ibiblio repository. I'll see if I can do the same for
hibernate. I typically don't push up artifacts for prominent OSS
projects from joe users.

-- 
jvz.

Jason van Zyl
[EMAIL PROTECTED]
http://maven.apache.org

happiness is like a butterfly: the more you chase it, the more it will
elude you, but if you turn your attention to other things, it will come
and sit softly on your shoulder ...

 -- Thoreau 


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to