Bootstrapping of the Scala compiler

Just a small reminder why downloading random binaries form the internet is a big no-no:

(This episode form the popular never ending Rust soap opera)

Please look through the comments and also consider the reactions, and the amount of people actually carrying about this indeed very severe issue.

Just imagine the people in charge of IT security, for example at big banks, health industry, and the like, would actually know that by using Scala they run in their production environments arbitrary, unsigned, not reproducible binaries created by random, foreign, anonymous people. (It’s very likely that the management actually does not know about the details, as just downloading and running arbitrary binaries is usually against legal policies at such entities…)

How it’s done elsewhere? Here’s an example of “doing it right”:

But Scala is still not part of the party. :frowning_face:

BTW. related: Scala 3 macro security

3 Likes