Skip to content

Conversation

@Thorium
Copy link
Member

@Thorium Thorium commented Oct 28, 2025

Potential security issue:
Someone could do some remote code execution attack by injecting their own program as fantomas-tool. Then execute that on part of build process via whatever new codebase repository build the victim is executing.

This PR adds some extra checks to pick the fantomas-tool.
Better than nothing, but this is not going as far as e.g. strong-name checks.

@nojaf
Copy link
Contributor

nojaf commented Oct 29, 2025

I'm not sure I want this, do you have an actual use-case for this?

@Thorium
Copy link
Member Author

Thorium commented Oct 29, 2025

This is theoretical security issue. I don't know the best solution. I'm lucky enough to not have seen any real-life usage.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants