|
|
|
|
|
by bonzini
809 days ago
|
|
That doesn't make build.rs any less of a juicy target for a supply chain attack. Arbitrary code downloaded from the internet and run at build time? That's a nightmare scenario for auditing, much worse than anything Autotools or CMake can offer. |
|