• moonpiedumplings@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      18 小时前

      Yes, that is true.

      Thought, even this remains problematic because cargo does execute build/compile time scripts, unsandboxed, that can be used to do malicious things, similar to the problems with npm.

      • locuester@lemmy.zip
        link
        fedilink
        English
        arrow-up
        7
        ·
        15 小时前

        But “you would have to reverse engineer binaries” is objectively false, since packages are source.

        I agree on your other point, but you really should edit the misinformation.