Supply-chain-attack risk
Supply-chain-attack risk
Posted Feb 12, 2025 22:19 UTC (Wed) by farnz (subscriber, #17727)In reply to: Supply-chain-attack risk by excors
Parent article: Rewriting essential Linux packages in Rust
One good feature of cargo vet in this respect is the ability to import trusted audits and maintain a registry of significant auditing entities; this enables a "big" entity who cares (like Google, for example), to publish a list of audits they've done that smaller projects can import.
Assuming that big projects adopt cargo vet, this allows smaller projects to "ride on their coattails" and shrink the exemptions list by trusting Google, Mozilla, or other big names to provide audits.
