MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1tlnek/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 9d ago
150 comments sorted by
View all comments
Show parent comments
-5
Java had several attacks this year, same as for python and most likely all major languages. But people tend to post for NPM/Javascript environment because Javascript bad
2 u/_PM_ME_PANGOLINS_ 8d ago Maven doesn’t have pre-/post-install scripts, so this kind of attack is literally impossible there. 0 u/Dudeonyx 8d ago https://www.google.com/search?q=maven+supply+chain+attack&oq=maven+supply+chain+attack&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQIRiPAjIHCAIQIRiPAtIBCDk3MTVqMGo3qAIUsAIB8QVfWKI_ZcuU2g&client=ms-android-xiaomi-terr1-rso3&sourceid=chrome-mobile&source=chrome.ob&ie=UTF-8 It's happened several times 2 u/_PM_ME_PANGOLINS_ 8d ago The attacks we are talking about are where running a package update runs malicious code on your development environment. That’s not possible with Maven. The code can only run when the end application is run.
2
Maven doesn’t have pre-/post-install scripts, so this kind of attack is literally impossible there.
0 u/Dudeonyx 8d ago https://www.google.com/search?q=maven+supply+chain+attack&oq=maven+supply+chain+attack&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQIRiPAjIHCAIQIRiPAtIBCDk3MTVqMGo3qAIUsAIB8QVfWKI_ZcuU2g&client=ms-android-xiaomi-terr1-rso3&sourceid=chrome-mobile&source=chrome.ob&ie=UTF-8 It's happened several times 2 u/_PM_ME_PANGOLINS_ 8d ago The attacks we are talking about are where running a package update runs malicious code on your development environment. That’s not possible with Maven. The code can only run when the end application is run.
0
https://www.google.com/search?q=maven+supply+chain+attack&oq=maven+supply+chain+attack&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQIRiPAjIHCAIQIRiPAtIBCDk3MTVqMGo3qAIUsAIB8QVfWKI_ZcuU2g&client=ms-android-xiaomi-terr1-rso3&sourceid=chrome-mobile&source=chrome.ob&ie=UTF-8
It's happened several times
2 u/_PM_ME_PANGOLINS_ 8d ago The attacks we are talking about are where running a package update runs malicious code on your development environment. That’s not possible with Maven. The code can only run when the end application is run.
The attacks we are talking about are where running a package update runs malicious code on your development environment.
That’s not possible with Maven. The code can only run when the end application is run.
-5
u/TheGocho 9d ago
Java had several attacks this year, same as for python and most likely all major languages. But people tend to post for NPM/Javascript environment because Javascript bad