Supply-chain-attack risk
Supply-chain-attack risk
Posted Feb 12, 2025 16:46 UTC (Wed) by excors (subscriber, #95769)Parent article: Rewriting essential Linux packages in Rust
This sounds unfortunately similar to Lord Farquaad from Shrek: "Some of you may die, but it's a sacrifice I am willing to make". The developers choosing to add convenient dependencies aren't going to be the ones suffering the costs of any such attacks, so I think there's some misalignment of incentives.
Hopefully any companies or large projects making use of this will be aware of the risk they're taking on, and will contribute to the tooling and code review and maintenance efforts needed to mitigate it. (Is there much activity around cargo-crev/cargo-vet nowadays, and is there anything better than that?)
