3 ms·
I'm one of the crates.io team members, and we're very grateful to Phylum for doing this analysis and alerting us! As a volunteer member, I'm also very thankful
by carols10cents 3y ago
I'm one of the crates.io team members, and we're very grateful to Phylum for doing this analysis and alerting us!
As a volunteer member, I'm also very thankful to the Rust Foundation for funding and hiring Walter Pearce, Adam Harvey, and Tobias Bieniek to work on security and crates.io (in varying proportions). They've helped lower our response time to incidents like this and made proactive improvements.
Regardless of any improvements they have or will make, there's always the possibility of malware getting through defenses. Reports are important to us, taken seriously, and handled as promptly as possible. More details here: https://www.rust-lang.org/policies/security https://www.rust-lang.org/policies/security
- louislang 3y agoResponse time was one of the best we've experienced at Phylum. It's obvious you guys are putting in a ton of work over there. Please let me know if there's anything we can help out with!