develooper Front page | perl.module-authors | Postings from November 2003

Re: [Module::Build] Re: How to indicate a dependency in my module

Thread Previous
From:
Phil.Moore
Date:
November 12, 2003 08:12
Subject:
Re: [Module::Build] Re: How to indicate a dependency in my module
Message ID:
16306.23438.802478.851230@zappa.ms.com
>>>>> "Chris" == Christopher Hicks <chicks@chicks.net> writes:

>> So, if I understand this correctly, you're worried about the build
>> process eval'ing the contents of a file I sent you.  Hmm.
>> 
>> OK, why is that anymore of a concern for eval'ing the perl module I
>> also distributed, too?  Isn't that just as big a security hole?  

Chris> There are any number of reasons I may be interested in
Chris> examining your module for extracting documentation and
Chris> dependancies without actually running a single line of your
Chris> code.  The safer we make this sort of thing the more things
Chris> like search.cpan.org and various more recent alternatives we'll
Chris> have.

Ok, that makes sense... Thanks.  I hadn't really though about using
this data outside of the build process.

Thread Previous


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About