5 ms·
> Who is funding this security audit? Are folks supposed to volunteer their free time? Same people who keep the whole rust project going, a lot of those are vo
by bcjdjsndon 2mo ago
> Who is funding this security audit? Are folks supposed to volunteer their free time?
Same people who keep the whole rust project going, a lot of those are volunteers aren't they? Not mad to think they could do the same for core packages at least
- aw1621107 2mo ago> Same people who keep the whole rust project going, a lot of those are volunteers aren't they? Sure, but from my understanding the Rust project is generally "bottom-up" in that volunteers generally work on what they want to rather than submit their time into a pool for some kind of higher-level management to direct.
- mirashii 2mo agoIt’s absolutely mad and extremely entitled to expect that a volunteer group of developers do an order of magnitude or more additional work for no additional pay or benefits to themselves.
- mabini 2mo ago[flagged]
- nicoburns 2mo agoThe core packages (things like rand and regex) are pretty closely audited in practice (albeit it might not catch a credential compromise). This crate isn't one of them.
- lyu07282 2mo ago> This crate isn't one of them. still caught in hours though, so just as a general rule: never install anything newer than 7 days old packages cargo feature for this is still unstable infuriatingly: https://github.com/rust-lang/cargo/issues/17009 https://github.com/rust-lang/cargo/issues/17009