• lemmysmash@piefed.social
    link
    fedilink
    English
    arrow-up
    13
    ·
    9 hours ago

    Usually yes, compilers and standard libraries are pretty safe. But if you use something like Google’s MLKit in your project, it’ll inject INTERNET permissions into your app’s manifest at compile time (even if your app itself doesn’t need it), and will spy on you.

  • hayvan@piefed.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    9 hours ago

    Besides surveillance and privacy, Google has a bit of a reputation for suddenly killing their projects.

    Programming languages should be mostly fine, even if they get abandoned a community fork can take up the slack. Anything popular enough finds maintainers.

  • dgdft@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    10 hours ago

    Google’s Golang team DDOS’d a bunch of people’s servers and then blamed them for it a few years back. YMMV in practice, but I think the behavior is pretty indicative of their SOP and how they treat users of their language tooling.

    Worth reading the issue tracker to see how callous the Googlers were about the whole thing (e.g. they banned the person who raised the issue).

    https://www.theregister.com/software/2023/02/02/sourcehut-nixes-plan-to-ban-grabby-go-module-proxy/1235899

  • endless_nameless@lemmy.world
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    11 hours ago

    Who knows? Technically, you can review the whole of these languages source code, but that doesn’t ensure anything. Tricks and backdoors can be hidden in plain sight VERY easily. Even if it’s safe now, it may not always be. If the future of your project is a concern, which it always should be, this should be a consideration.

    Surveillance aside, Google giveth and Google taketh away. We can’t trust them not to fuck us over with some legal / licensing bullshit tomorrow.