logoalt Hacker News

bethekidyouwanttoday at 4:26 AM1 replyview on HN

tasks.json is the problem here, who thought that was a good idea?


Replies

paul_htoday at 7:19 AM

Agree. But the first build you do after that clone/checkout is risky too. Maybe not as wide open, as the build-tool makers are a line of defence if they're acting on classes of vuln.