`npx create-framework-app` Is prime for disruption where instead of downloading and executing unknown code it can defer the work to a cloud function that generates a file tree and ships it down to the customers machines. This changes the trust model significantly.
-
Show this thread
-
-
Also does this really change anything at all. File generation happens in the cloud but that could still generate malicious code that is sent to the customers boilerplate.
4 replies 1 retweet 14 likes -
I think this is actually *less* secure. With open source boilerplate, at least other people can review the code for hacks. With a server generating a template, you could have the server insert a rootkit only for a small subset of targeted users.
1 reply 0 retweets 1 like -
To be clear nothing preventing this from happening today with life-cycle scripts. Anyway I agree there are cons to this approach as well. However I still think downloading code to execute a scaffold command feels odd.
1 reply 0 retweets 0 likes
Setting up and maintaining some cloud infrastructure to perform scaffolding generation also feels odd
-
-
Sounds like an opportunity to me
0 replies 0 retweets 2 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
he/him 