Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

build.rs is easier to read, but it's the tip of the iceberg when it comes to auditing.

If I were to sneak in some underhanded code, I'd do it through either a dependency that is used by build.rs (not unlike what was done for xz) or a crate purporting to implement a very useful procedural macro...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: