Skip to content

How to run this securely?Β #37

@qbolec

Description

@qbolec

So, you ask me to download your app and run it on my computer, and trust you everything will be fine?
Isn't that what got me in trouble in the first place? :)

Yes, in theory I could review the source code here, but I am not a Java expert, and it looks like there's already hundreds of lines of "code" and "configs" in this repo, and I have no time to learn how to do that.

What's the safe way to run this scan?

  1. Can I for example run it in "read-only" + "no access to internet" way? If so, how can I use OS help to achieve the two goals?
  2. Is there perhaps some simple set of strings we are simply grepping for, and I could pass to grep/ack or some other existing tool?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions