4 ms·
The only really shocking part of this is that Artifactory is vulnerable to this. I expect developers to be lazy about build security because I've seen it over a
by PhineasRex 6y ago
The only really shocking part of this is that Artifactory is vulnerable to this. I expect developers to be lazy about build security because I've seen it over and over again at multiple companies, but Artifactory's whole purpose is to provide secure build dependency management.
I'll be rethinking using Artifactory in my infrastructure.
- HereBeBeasties 6y agoA good look at their (public) bug tracker might change your mind about how surprising this is.