4 ms·
There are projects like crev [0] which attempt to get around this by using a web of trust to audit dependencies. Rust has cargo-crev [1] as an implementation.
by karlding 6y ago
There are projects like crev [0] which attempt to get around this by using a web of trust to audit dependencies. Rust has cargo-crev [1] as an implementation.
Here's the previous HN discussion [2].
[0] https://github.com/crev-dev/crev/ https://github.com/crev-dev/crev/
[1] https://github.com/crev-dev/cargo-crev https://github.com/crev-dev/cargo-crev
[2] https://news.ycombinator.com/item?id=18824923 https://news.ycombinator.com/item?id=18824923
- parksy 6y agoThanks, I hadn't come across crev. I have always worried that open review systems could create a false sense of security, if enough bad-faith actors poison the well. But it looks like crev deals with this by allowing users to choose their circle of trust, which is an interesting concept, definitely following this project and will take a deeper dive into it. Cheers :)