What are the risks and possibilities or scenarios whereby someone sets up masquerades of maven repositories and/or ip streams to provide masqueraded library copies of the original but injected with malicious or harmful code.

What are the steps and practices to prevent such risks and possibilities?

Edit
Report