17 karma · joined March 17, 2019
Someone could release a malicious package that looks okay to a scanner tool, but when installed using uv can behave differently, allowing attackers to masquerade executable code.
In addition, for OCI images, it is possible to produce an OCI image that can overwrite layers in the tar file, or modify the index. This could be done in a way that is undetectable by the processor of the OCI image. Similar attacks can be done for tools that download libraries, binaries, or source code using the vulnerable parser, making a tar file that when inspected looks fine but when processed by a vulnerable tool, behaves differently.
I hope that answers your question?
Finally, if you wanted to, you could run gVisor within Edera Protect, but we feel that Edera Protect would already provide the security benefits that gVisor offer.
For me, I never fitted in with anyone at University and felt alone. Going into work I started with small companies, providing tech for sales roles. The sales way of ‘high pressure’ was transferred to how projects should be managed.
Today I try and help out by building a community via running a meet-up. The people I have around me today and the confidence I have to be able to be depressed and get out of it with the help of others around me keeps me going.