Supply-chain-attack risk
Supply-chain-attack risk
Posted Feb 12, 2025 22:48 UTC (Wed) by koverstreet (subscriber, #4296)In reply to: Supply-chain-attack risk by farnz
Parent article: Rewriting essential Linux packages in Rust
The next incremental improvement will be adding gpg style "web of trust"; you trust people you know who vet their dependencies, and recursively trust the people they trust (by an amount that falls off with distance, people that trust them, what have you).
Couple that with tools that show you "you have x dependencies that haven't been sufficiently vetted" (or have had significant changes since then), and we could efficiently farm out the auditing.
