Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Do not run any Cargo commands on untrusted projects (shnatsel.medium.com)
6 points by ljahier 8 months ago | hide | past | favorite | 2 comments


I am not sure I understand. If you don't trust the project to the point where you think they may inject malicious code into the local cargo config file, why would you trust the source code you are building?

At the end of the day, you build code to run it. If you don't trust the code you build, probably you should not build it in the first place?


In other news water is wet…




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: