3 ms·
You're not wrong for the individual laptop case. But there's a lot of systems out there that download code, inspect a text, YAML, Dockerfile, or whatever kind o
by bhuga 8y ago
You're not wrong for the individual laptop case. But there's a lot of systems out there that download code, inspect a text, YAML, Dockerfile, or whatever kind of file, then sandbox it to run it. That's more or less how most CI systems work, and this vulnerability happens before the sandbox.
- TooBrokeToBeg 8y ago> But there's a lot of systems out there that download code, inspect a text, YAML, Dockerfile, or whatever kind of file, then sandbox it to run it. I've never seen this. It smacks of terrible practice that would not last long in a daily CI system. Once you have a good version, locking on to that version is one thing. Just randomly downloading new code versions for a daily build is impractical.