Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upCrate Trustworthiness #6
Comments
This comment has been minimized.
This comment has been minimized.
burdges
commented
Dec 5, 2018
|
I'd expect crates.io to becoming an attack vector eventually, ala npm. I've two questions: Would name spaces alleviate this attack vector? It's tricky. Imagine I do not release Are micro-repos a security threat that contributes to |
This comment has been minimized.
This comment has been minimized.
Shnatsel
commented
Jan 6, 2019
|
Relevant discussion on crates.io bug tracker: rust-lang/crates.io#75 https://github.com/dpc/crev which may solve it for companies with a security department reviewing incoming code |
tarcieri commentedOct 16, 2018
•
edited
I think the issue of "which crates can we trust", where trust is some sort of crate reputation system, came up a lot in the discussions I participated in so far in the forming of this WG.
Here's a relevant incident which just occurred:
https://internals.rust-lang.org/t/crates-io-incident-2018-10-15/8568
Sorry for such a vague and open-ended topic, but perhaps we can break it down into a few more tangible issues.