23
Any suggestions for a self-hosted CI that can also be run locally?
(programming.dev)
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Follow the wormhole through a path of communities !webdev@programming.dev
I know what you mean, but do you not read the diff? Are you working on codebases that are so obfuscated that you can't spot a malicious command?
What if they pull in a new dependency with a CVE or that executes malicious code? How am I supposed to check that? Or what if I miss a bug in the justfile or shell script?
Anti Commercial-AI license
Run your CI in a sandbox.
For example gitlab allows you to run in a docker image.
Unless the attacker knows a docker CVE or is willing to waste a specter style 0-day on you, the most they can do is waste your cpu cycles.
Yep. Hell, be very paranoid and run it in a container on a runner VM on your box if you like.
And you can use podman or sysbox there.