3 ms·
The crates.io page and version history should have an entry, like red with an ! and a cross through with an advisory note explaining the security issue, accessi
by survirtual 1mo ago
The crates.io page and version history should have an entry, like red with an ! and a cross through with an advisory note explaining the security issue, accessible via the api as well so it is clear what happened.
The main crate entry should also contain a security advisory at top. I looked at the crate and it just looked normal; I had to dig to find the exact impact surface, and if I wasn't informed via secondary means (hackernews) I would not have known. This is unacceptable for a mature package management system.
Luckily I was unaffected in this case.
- Manishearth 1mo agocargo-audit is the automated mechanism you are looking for The crate does have an advisories/"security" page on crates.io. We could try and show the existence of a security-deleted crate on the page. This is not a priority for anyone, and I remain unconvinced that it needs to be (not that that is my decision anyway). File an issue and make your case to the crates.io team.