|
|
|
|
|
by dist-epoch
7 days ago
|
|
Agent can get tricked into using a malicious library in your project, commit and push that, which you then run outside the VM. So if you ever run the repo code outside the VM and don't review everything committed, you are still at danger. |
|
But good call-out if someone uses a different workflow.