> Are you not concerned about an asteroid impact rendering you extinct during your next Rust build? Why not? That's the same level of relevance as your supposed concern.
That’s a strawman argument and you’re still dodging the question.
> You need to act like it is compromised in all cases, just like everything else.
No. I act like compromised code is a legitimate risk regardless of how well your build pipeline is sandboxed.
I don’t understand why this is a hard concept for you to grasp.
> So your version is "we trust everyone and don't verify anything". Yeah, that's going to work. By your "logic" firewalls wouldn't be necessary.
That’s the literal opposite of my point (as well as another strawman).