Remix.run Logo
lrvick 5 days ago

Downloading binaries as part of an installation of a scripting language library should always be assumed to be malicious.

Everything must be provided as source code and any compilation must happen locally.

oulipo2 5 days ago | parent [-]

Sure, but then you need to have a way to whitelist

lrvick 5 days ago | parent [-]

The whitelist is the package-lock.json of the hashes of libraries you or a security reviewer you trust has reviewed.