|
|
|
|
|
by monocasa
1030 days ago
|
|
> Sandboxing doesn't completely prevent supply-chain attacks. Correct, it's more a defense in depth technique, not a complete defense. > On all developer machines as well? No. Very few big orgs do this and only for mission-critical stuff. All builds at Google for instance use the model I laid out including 'developer builds'. |
|
That would be extremely useful as the analyzer is a pretty juicy target and also runs proc-macros/build.rs scripts.
[1] https://github.com/bazelbuild/rules_rust/pull/384
[2] https://bazelbuild.github.io/rules_rust/rust_analyzer.html