• moonpiedumplings@programming.dev
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 hours ago

    Yes, that is true.

    Thought, even this remains problematic because cargo does execute build/compile time scripts, unsandboxed, that can be used to do malicious things, similar to the problems with npm.

    • locuester@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 hours ago

      But “you would have to reverse engineer binaries” is objectively false, since packages are source.

      I agree on your other point, but you really should edit the misinformation.