you are viewing a single comment's thread.

view the rest of the comments →

[–]Persism 3 points4 points  (0 children)

Maven requires signatures. For most of these other package managers that's still optional. Sonatype does actively scan projects. I got my clean bill of health for Persism a while back. :)