7 ms·
(as I and others have mentioned in the thread): The attacker can just move the malicious code from build.rs to lib.rs (ie. build-time -> test/execution-time).
by jaen 27d ago
(as I and others have mentioned in the thread): The attacker can just move the malicious code from build.rs to lib.rs (ie. build-time -> test/execution-time).
Then the problem is the language, as the grandparent observes.
- cpuguy83 27d agoSure, but I don't expect build to execute arbitrary code. That's a big difference. It's like if `git clone` ran random stuff from the cloned repo.