← Back to context

Comment by halflife

3 months ago

This sucks for libraries that download native binaries in their install script. There are quite a few.

Downloading binaries as part of an installation of a scripting language library should always be assumed to be malicious.

Everything must be provided as source code and any compilation must happen locally.