Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can tell it is lots of "fun" when you can only use a Maven mirror, with approved jars.

To get a jar into that mirror, a request needs to be sent to the legal team describing the license and business case use, after approval the IT team will add the said jar to the mirror.

The same applies to version upgrades of already approved jars.

This is a typical scenario I had already in a couple of projects.



I agree that this sucks, but not doing it that way is dangerous for the company because developers might not care enough about license compliance when they include some stuff into their project.


I also agree, as I have been through what happens when developers do exactly that and then it gets discovered the worse way.


You willingly subject yourself to this? Why?


Just a guess: it pays the rent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: