Skip to content
This repository has been archived by the owner on Feb 12, 2022. It is now read-only.

Transient dependencies are not verified. #33

Open
ghost opened this issue May 11, 2019 · 0 comments
Open

Transient dependencies are not verified. #33

ghost opened this issue May 11, 2019 · 0 comments

Comments

@ghost
Copy link

ghost commented May 11, 2019

Correct me if I'm wrong, but I don't think the pom/transient dependencies are verified. A malicious repo could edit a pom, add a new transient dependency without triggering a verification failure. The newly created dependency will not exist in the dependencyVerification block and therefore not be checked.

The pom (or some transient dependency list) would need to also be verified, not just the jar files.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

0 participants