When you want to run some code from a non-trusted source like some github repo, what sorts of precautions do you think are sufficient?

@internic ... I usually review the code in the github account....

Follow

@mathaetaes So take it to be implicit here that the intent is to mitigate the risk beyond whatever you can do by looking at the code. (Honestly, I think people overestimate their ability to spot malicious code.)

@internic Fair point, though I find vulnerabilities and shenanigans in source code for a living. :)

I do have a VM for "questionable" software... though that's usually used for software that I trust, but that I don't trust will clean up after itself when I try to remove it. Autodesk software is the primary vendor for that VM...

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.