top | item 39115259

(no title)

rustman123 | 2 years ago

They intentionally added a copyleft-licensed library (options-ext) written by himself to poison the supply chain via `dirs-sys`. (Commit: https://github.com/dirs-dev/dirs-sys-rs/commit/e169da7af901e...)

The dependency adds nothing of value and can trivially be removed. (https://github.com/dirs-dev/dirs-sys-rs/pull/22/files)

When asked about it, they claim to prefer MPL and that the current license was an accident they 'may or may not correct'.

Popular dependents include - cross (https://crates.io/crates/cross) - terminfo (https://crates.io/crates/terminfo)

discuss

order

No comments yet.