Conversation

Show replies
This Tweet was deleted by the Tweet author. Learn more
I don't see anything in Deno's docs about running library code without granting it the same authorities as the code that invoked it, so that malicious library code is safe to run. Can one of you point me to the relevant part of the docs?
1
1
Show replies
Replying to and
In this case, the malicious code ended up in vscode - so stealing bitcoin was really quite restrained as far as these things go.
1
1