3 ms·
Surely non-sandboxed build scripts are just a terrible idea. Both Cargo and npm should look at what Swift Package Manager (SPM) is doing. It’s not perfect but
by willtemperley 1mo ago
Surely non-sandboxed build scripts are just a terrible idea.
Both Cargo and npm should look at what Swift Package Manager (SPM) is doing.
It’s not perfect but there’s a noticeable absence of supply chain attacks involving SPM, probably partly because it doesn’t use a mutable registry, but I suspect attacks are just more difficult. On the rare occasion a build script is involved it’s run in a sandboxed plugin.
- wronex 1mo agoWhy would a malicious library author limit their maliciousness to the build script?
- deleted 1mo ago[deleted]
- willtemperley 1mo agoThey wouldn't, but build scripts are a particularly effective attack vector.
- 0rzech 1mo agoThey won't, but the less attack vectors, the better.