• moonpiedumplings@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 hour ago

      Yes, that is true.

      Thought, even this remains problematic because cargo does execute build/compile time scripts, unsandboxed, that can be used to do malicious things, similar to the problems with npm.