3 ms·
I don't expect D to change the way it does things. But I think your security concerns lack merit. It doesn't make sense to produce an executable, not execute
by SubjectToChange 5y ago
I don't expect D to change the way it does things. But I think your security concerns lack merit.
It doesn't make sense to produce an executable, not execute it, then go audit the code. Just audit the code in the first place. And like I mentioned earlier, virtually no project is purely static code. They include shell scripts, make files, and tons of other things. Working with untrusted code is dangerous, period. Making compile-time programming a little safer is just passing the buck.
- WalterBright 5y ago> It doesn't make sense to produce an executable, not execute it, then go audit the code. If you're auditing the code by examining it with an IDE, it could certainly get compiled.
- SubjectToChange 5y agoMany IDEs automatically start the produced executable too. Again, I don't understand why you'd want to wait until you have an unwanted/untrusted executable to begin auditing code.