4 ms·
>> Maven repository, etc are a wild west. I'd disagree with this one being characterised along with the others. When i want to publish on Maven Central, i have
by CraigJPerry 3y ago
>> Maven repository, etc are a wild west.
I'd disagree with this one being characterised along with the others. When i want to publish on Maven Central, i have to:
1. Prove i own the domain i'm about to upload a package under, e.g. if i claim com.myname - then i'm going to need to prove that to Maven Central by creating a DNS TXT record on com.myname
2. Sign my release - every jar i publish needs to be signed by my (or my org's) GPG key
3. On top of the automated mechanical controls, there's an actual human sign off in the loop for the registration process at least
This might still leave attacks like typo-squatting potentially open but not an easy thing to do and it effectively stops most of the other horrors like replacing an already published artifact with a malicious version, or "brand-jacking" my library's name and pushing up a new malicious release.
- cmrdporcupine 3y agoYes, that's fair, Maven did start with a better story than others in terms of authenticity of sources, etc. Crates.io doesn't even have the concept of an organizational namespace. It's ridiculous. But Maven still has the broader cultural problem of automatic dep resolution: it's just too easy to go adding deps for every little utility and nifty function or feature or framework.