• Corngood@lemmy.ml
    link
    fedilink
    arrow-up
    6
    ·
    vor 4 Monaten

    Is there a reason you’re suspicious about that particular dependency, or are you just asking about dependencies in general?

    • GolfNovemberUniform@lemmy.ml
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      edit-2
      vor 4 Monaten

      I’m worried about that one specifically. Dependencies in general can be suspicious if they come from untrusted sources but in that case it’s suspicious by being related to testing (like the xz thing was) that shouldn’t even be in a released app anyways.

      • pingveno@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        vor 4 Monaten

        It’s not included in the final build artifact. It’s a Gradle plugin.