setup-maven icon indicating copy to clipboard operation
setup-maven copied to clipboard

External binaries in the source path

Open gst-de opened this issue 10 months ago • 0 comments

After looking through the sources I have a question / problem witht the code. In general it is a bad practice to add executables to your sources. Especially in the time of the xz-lib-backdoor adding an exteranl tool like stCarolas/setup-maven/blob/master/node_modules/%40actions/tool-cache/scripts/externals/7zdec.exe to the code should be avoided.

gst-de avatar Apr 22 '24 14:04 gst-de