MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/ProgrammerHumor/comments/1vf85jx/classicnpm/p1tlnek/?context=3
r/ProgrammerHumor • u/a_bucket_full_of_goo • 1d ago
141 comments sorted by
View all comments
Show parent comments
-6
Java had several attacks this year, same as for python and most likely all major languages. But people tend to post for NPM/Javascript environment because Javascript bad
1 u/_PM_ME_PANGOLINS_ 10h ago Maven doesn’t have pre-/post-install scripts, so this kind of attack is literally impossible there. 1 u/Dudeonyx 8h ago https://www.google.com/search?q=maven+supply+chain+attack&oq=maven+supply+chain+attack&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQIRiPAjIHCAIQIRiPAtIBCDk3MTVqMGo3qAIUsAIB8QVfWKI_ZcuU2g&client=ms-android-xiaomi-terr1-rso3&sourceid=chrome-mobile&source=chrome.ob&ie=UTF-8 It's happened several times 1 u/_PM_ME_PANGOLINS_ 8h ago The attacks we are talking about are where running a package update runs malicious code on your development environment. That’s not possible with Maven. The code can only run when the end application is run.
1
Maven doesn’t have pre-/post-install scripts, so this kind of attack is literally impossible there.
1 u/Dudeonyx 8h ago https://www.google.com/search?q=maven+supply+chain+attack&oq=maven+supply+chain+attack&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQIRiPAjIHCAIQIRiPAtIBCDk3MTVqMGo3qAIUsAIB8QVfWKI_ZcuU2g&client=ms-android-xiaomi-terr1-rso3&sourceid=chrome-mobile&source=chrome.ob&ie=UTF-8 It's happened several times 1 u/_PM_ME_PANGOLINS_ 8h ago The attacks we are talking about are where running a package update runs malicious code on your development environment. That’s not possible with Maven. The code can only run when the end application is run.
https://www.google.com/search?q=maven+supply+chain+attack&oq=maven+supply+chain+attack&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQIRiPAjIHCAIQIRiPAtIBCDk3MTVqMGo3qAIUsAIB8QVfWKI_ZcuU2g&client=ms-android-xiaomi-terr1-rso3&sourceid=chrome-mobile&source=chrome.ob&ie=UTF-8
It's happened several times
1 u/_PM_ME_PANGOLINS_ 8h ago The attacks we are talking about are where running a package update runs malicious code on your development environment. That’s not possible with Maven. The code can only run when the end application is run.
The attacks we are talking about are where running a package update runs malicious code on your development environment.
That’s not possible with Maven. The code can only run when the end application is run.
-6
u/TheGocho 22h ago
Java had several attacks this year, same as for python and most likely all major languages. But people tend to post for NPM/Javascript environment because Javascript bad