liberapay.com icon indicating copy to clipboard operation
liberapay.com copied to clipboard

Protection of developers from the possibility of malicious code in dependencies

Open Changaco opened this issue 2 months ago • 0 comments

Liberapay's README currently states:

It's up to you to isolate your development environment from the rest of your system in order to protect it from possible vulnerabilities in the testing dependencies.

That's unsatisfactory. If venvjail pans out, Liberapay should probably use it by default. In the meantime, there should be at least one documented way to set up a sandbox to contain possible exploits.

Changaco avatar Apr 19 '24 12:04 Changaco