Hacker News new | past | comments | ask | show | jobs | submit login

Dash looks like a great project but the community doc contributions are a security concern. Docs are uploaded to git as Tars, nothing is stopping someone from adding malicious code to these tar uploads which developers will download unknowingly when they add a community doc.

See: https://github.com/Kapeli/Dash-User-Contributions




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: