Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
vips7L
61 days ago
|
parent
|
context
|
favorite
| on:
Axios compromised on NPM – Malicious versions drop...
AFAIK maven doesn’t support post install logic like npm does. You have to explicitly optin with build plugins. It doesn’t let any arbitrary dependency run code on your machine.
himata4113
61 days ago
[–]
some post processors have chains to execution (ex: lombok)
vips7L
60 days ago
|
parent
[–]
You explicitly opt in by using a compiler plugin. Merely having it as a dependency, like in npm, doesn’t mean it can run code at build time.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: