5 ms·
From a glance at the GitHub page, it looks like you can self-host the project. Is "bower install" a possible attack vector as well? I'm unfamiliar with it.
by no_protocol 10y ago
From a glance at the GitHub page, it looks like you can self-host the project. Is "bower install" a possible attack vector as well? I'm unfamiliar with it.
- the_duke 10y agoBower is a package manager for Javascript libraries. So the only attack vector would be a MIT attack, intercepting the requests to the Bower registry.
- deleted 10y ago[deleted]
- Diederich 10y agoVery good, thanks!
- no_protocol 10y agoOr a hijacked GitHub repository/maintainer?