My Lemmy Oracle
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
thomask@lemmy.sdf.org to Rust@programming.devEnglish · 1 year ago

999 crates of Rust on the wall

lawngno.me

external-link
message-square
4
fedilink
49
external-link

999 crates of Rust on the wall

lawngno.me

thomask@lemmy.sdf.org to Rust@programming.devEnglish · 1 year ago
message-square
4
fedilink
tl;dr
alert-triangle
You must log in or register to comment.
  • ericjmorey@programming.dev
    link
    fedilink
    arrow-up
    9
    ·
    1 year ago

    I’ve been comparing crates on crates.io against their upstream repositories in an effect to detect (and, ultimately, help prevent) supply chain attacks like the xz backdoor1, where the code published in a package doesn’t match the code in its repository.

    The results of these comparisons for the most popular 9992 crates by download count are now available. These come with a bunch of caveats that I’ll get into below, but I hope it’s a useful starting point for discussing code provenance in the Rust ecosystem.

    No evidence of malicious activity was detected as part of this work, and approximately 83% of the current versions of these popular crates match their upstream repositories exactly.

  • BB_C@programming.dev
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    1 year ago

    Good work.
    I don’t know if kornel* still lurks here, but I think he did/does related/similar analysis for https://lib.rs.

    * @[email protected] / @[email protected]

    • Kornel@mastodon.social
      link
      fedilink
      arrow-up
      6
      ·
      1 year ago

      @BB_C Yes, implemented here: https://gitlab.com/lib.rs/main/-/blob/main/tarball/src/comparator.rs?ref_type=heads

Rust@programming.dev

rust@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Welcome to the Rust community! This is a place to discuss about the Rust programming language.

Wormhole

[email protected]

Credits
  • The icon is a modified version of the official rust logo (changing the colors to a gradient and black background)
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 20 users / day
  • 67 users / week
  • 382 users / month
  • 2.88K users / 6 months
  • 1 local subscriber
  • 7.13K subscribers
  • 934 Posts
  • 4.43K Comments
  • Modlog
  • mods:
  • snowe@programming.dev
  • Ategon@programming.dev
  • EdTheLegendary@programming.dev
  • kahnclusions@programming.dev
  • torcherist@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org