4 ms·
The actual build that you provide to customers will run code from many/most/nearly all of them, I think your dev machine is the least of your worries
by throwaway821909 5y ago
The actual build that you provide to customers will run code from many/most/nearly all of them, I think your dev machine is the least of your worries
- bpicolo 5y agoThat's definitely relevant for nodejs apps, but running js client side is a very different risk profile from running arbitrary scripts on the computer or server doing an npm install.
- noodlesUK 5y agoYou might think that, but if we’re talking about a frontend service that doesn’t really handle much sensitive info (if any), there’s a lot juicier stuff on my machine than just pushing malware to that codebase (not least other codebases on my machines)