Hacker News new | ask | show | jobs
by estebank 33 days ago
This kind of thing is one of the reasons crates.io distributes source only, and that published crate dependencies can't depend on other repositories (that might allow for that attack).