You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We do not want to run any mvn commands in the post-processor that use code from the repository. owl-bot runs in a privileged (albeit limited) environment and you can craft a pom.xml such that it loads malicious plugins that run arbitrary code.
For this reason, we included the java formatter jar in the post-processor image and ran it directly.
We can eliminate the discrepancy between the two if owlbot-java uses the formatter defined in the project:
The text was updated successfully, but these errors were encountered: