DEV Community

Discussion on: Rspack: The Rust-Based Web Bundler that Combines High Performance with Interoperability

Collapse
 
daguyfmny_31 profile image
Daguyfmny

Has ByteDance any plans to spy thru it?

Collapse
 
imsuvesh profile image
Suvesh K

Did you missed the word Open Source ?

Collapse
 
zachbryant profile image
Zach • Edited

Open source doesn't automatically mean safe. Doesn't guarantee that the downloaded/published binaries are free from injected code, for example. If it's unsafe, it would be cleverly disguised. An auditor would just have to be more clever.

Dont forget this is a company that has to obey the political and military interests of the CCP.

Collapse
 
mattccc profile image
Matt C

The question one would probably want to ask is if you want to run a Rust from a cn company on your local machine. Unless you trust your infra better than the NPM registry one. I don't trust either of them.