summaryrefslogtreecommitdiff
path: root/doc/todo/concurrent-output_dependency_implies_compilation_of_a_lot_of_unstrusted_sources_as_root.mdwn
blob: d8493b274b773f024fa35c105d2aeb424773f76a (plain)
1
2
3
4
5
The recent dependency on concurrent-output adding implies downloading, compiling, and executing as root of many (MissingH, hslogger, process, unix-compat, network, directory, ansi-terminal, unix, ...)  unstrusted sources. This seems like a huge security problem...

Are these at least downloaded using https?

> [[done]] --[[Joey]]