Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
thehardsphere
on Sept 15, 2017
|
parent
|
context
|
favorite
| on:
Malicious software libraries found in PyPI posing ...
I thought Maven enforces signatures? Though that doesn't fully mitigate the risk as you still have to trust the signer.
Consider applying for YC's Spring batch! Applications are open till Feb 11.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: