top | item 39830294

(no title)

curun1r | 1 year ago

The “someone else” also needs to be vetted to ensure that their first update won’t include crypto mining malware.

We should remember that an unmaintained dependency isn’t the worst thing that can happen to a supply chain. There are far worse nightmare scenarios that involve exfiltrated keys, ransomewared files and such.

I’ll bet that if someone with a track record of contributing to the Rust community steps up, he’ll happily transfer control of the crate. But he’s not just going to assign it to some random internet user and put the whole ecosystem at risk.

discuss

order

No comments yet.