Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From a glance at the GitHub page, it looks like you can self-host the project. Is "bower install" a possible attack vector as well? I'm unfamiliar with it.


Bower is a package manager for Javascript libraries.

So the only attack vector would be a MIT attack, intercepting the requests to the Bower registry.


Or a hijacked GitHub repository/maintainer?


Very good, thanks!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: