3 ms·
The big problem here is really the library distribution system for java. Most jvm based projects use binary dependencies that are mostly sourced from maven cent
by diffxx 4y ago
The big problem here is really the library distribution system for java. Most jvm based projects use binary dependencies that are mostly sourced from maven central. A build tool could automatically block downloads of, or construction of a classpath including, binaries with known vulnerabilities. But then you might find yourself with a broken build that you can't fix yourself leaving you at the mercy of the developers of an upstream dependency that you inadvertently depend on (like log4j). I think the situation would be a lot better if java projects defaulted to source dependencies instead of binary dependencies and build tools were good at supporting remote binary caching so that you could build your own cache of binary artifacts rather than rely on a central one (so that not everyone in your org needs to burn cpu rebuilding libraries with each update). Then even if you indirectly depend on log4j, you could just grep your codebase for log4j, bump the version, rebuild everything and move on with your life. This also could make life easier for maintainers since downstream users might just fix things for them.