3 ms·
As mentioned by others it’s just as easy for an attacker to modify a crate’s runtime code.
by praseodym 1mo ago
As mentioned by others it’s just as easy for an attacker to modify a crate’s runtime code.
- vlovich123 1mo agoSo? Runtime code requires actually executing the malicious code path which isn’t an immediate 100% hit rate for everyone that includes it in the dependency chain. For build.rs it’s a 100% compromise of everyone it’s in the dependency chain for. Additionally, at runtime you may not have access to secrets whereas at build time you most certainly do.
- dgrunwald 1mo agoThe malicious code could use life-before-main hacks to gain code execution if it's linked at all, even if uncalled. https://grack.com/blog/2026/06/11/life-before-main/ https://grack.com/blog/2026/06/11/life-before-main/
- vlovich123 1mo agoIt doesn’t take away from the point that build time often has access to secrets the runtime does not.