elharo commented on PR #444:
URL: 
https://github.com/apache/maven-dependency-plugin/pull/444#issuecomment-2416628646

   The goal is to block direct pushes to master. If the release process 
requires doing that, then yes, we might need to adjust the release process 
first, which we should do. Direct commits to master are a risk for supply chain 
attacks. Discussion is ongoing on the dev list. 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscr...@maven.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org

Reply via email to