const compile_version = gorge "git describe --tags --always --dirty"
const compile_time = gorge "date --rfc-3339=seconds"Often this arbitrary code is to do things like run "pkg-config --libs" or such to find dependencies to link against, or generate some files that shouldn't be checked into source code, but rarely does it have sandboxing or other restrictions.
Languages, like Go, which don't let a package execute arbitrary code on installation are the exception.
Go does stand in contrast to this. `go get` and `go build` cannot execute arbitrary code, and if you use those two commands to build untrusted code, in theory your machine should still remain uncompromised. They release CVEs for any issues here (such as https://github.com/golang/go/issues/29231).
Of course, if you run the code you compiled, that is unsafe, but just compiling it is supposed to be fine.
-buildinfo=false
I especially found out this is really useful for extracting information form non-stripped firmware binaries. They lay around on some S3 buckets, where cheap IoT manufacturers think it's safe to expose them online for updating purposes...
> the currently checked-out revision and a flag indicating whether edited or untracked files are present
Basically, it's including a git commit ID, which is a hash, and flags that indicate if there are local changes.
It's pretty common to include build hashes in shipping code, logs, ect.