Supply-chain-attack risk
Supply-chain-attack risk
Posted Feb 13, 2025 9:20 UTC (Thu) by taladar (subscriber, #68407)In reply to: Supply-chain-attack risk by excors
Parent article: Rewriting essential Linux packages in Rust
There is a hidden cost to those internal versions of functionality that could be a well vetted and tested dependency too though, they are just generally not considered by projects trying to argue that any dependency is bad. It is much more likely that your half-thought out internal code you just wrote for a single user has some bad design flaws and security holes and critical bugs than a library used by thousands of others.
