-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Audit dependencies for unsigned artifacts #1608
Comments
There's one unsigned dependency from Central, presumably from the bad old days when they let all kinds of crap in: The rest of the deps are from Clojars; mostly from Leiningen contributors:
The first three libs there are simply there to support templates. I'm considering swapping out stencil for another moustache lib since this would also solve #1563 which I have no idea how else to solve. |
Wow, total crickets on all seven issues. Disappointing. |
The dependency landscape has naturally shifted over the years, and I’m sad to report the situation has not improved. (I kind of expected that the passing of time would have taken care of this, but no.) It may be legitimate to question whether this issue is still actionable given the culture. No further action from me.
|
Yeah, I don't think there's much we can do about this if authors are unresponsive. |
It's kind of crappy that we have dependencies for which we can't verify the provenance.
We should open bug reports with each unsigned library encouraging them to publish signed versions.
The text was updated successfully, but these errors were encountered: