`npx create-framework-app` Is prime for disruption where instead of downloading and executing unknown code it can defer the work to a cloud function that generates a file tree and ships it down to the customers machines. This changes the trust model significantly.
-
Show this thread
-
-
Also does this really change anything at all. File generation happens in the cloud but that could still generate malicious code that is sent to the customers boilerplate.
4 replies 1 retweet 14 likes -
Replying to @sebmck
yes, the hypothesis is that the shipped scaffold to the user will have a far smaller footprint compared to the code for the scaffold + the actual scaffolded code. Additionally with this approach a download of files requires no runtime to view the output.
1 reply 0 retweets 0 likes
Replying to @samccone
So the expectation is that someone still hand reviews the generated code? What do you mean it requires no runtime? You eventually execute it.
12:22 PM - 16 Oct 2019
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
he/him 