Y
Hacker News
new
|
ask
|
show
|
jobs
by
estebank
33 days ago
This kind of thing is
one
of the reasons crates.io distributes source only, and that published crate dependencies can't depend on other repositories (that might allow for that attack).