|
|
|
|
|
by r2vcap
37 days ago
|
|
From a supply-chain perspective, Cargo is still in the same broad risk category as npm and PyPI: installing packages means trusting externally published code, including code that may execute during build or installation. Rather than looking for someone to blame - in this case, GitHub - we should focus on constructive ways to harden the ecosystem. |
|
The gripe with using GitHub auth for crates.io is that GitHub is owned by a large, fickle corporation with a (shall we say) complicated history with open source, and people object on principled grounds to being forced to use GitHub in order to participate in the crates.io ecosystem.