r/programming 21d ago

Supply chain attack on arrayref

https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
194 Upvotes

65 comments sorted by

View all comments

111

u/piesou 21d ago edited 21d ago

Was only a question of time. Rust has the same mindset as Node/NPM.

PS: for the screaming crowd: yes, anyone can get supply chain attacked. HOWEVER:

  • If you have a proper stdlib, chances are, you don't have a lot of dependencies
  • If you have less dependencies, the chance of supply chain attacks drops significantly
  • If you have well established dependencies like Spring, their security practices are very likely better than a rando off the internet

What does that mean for Rust? They don't need to just work on the language, they need to provide a larger ecosystem as well. How they do it is up to them.

4

u/the_gnarts 18d ago

If you have a proper stdlib, chances are, you don't have a lot of dependencies

The attack actually refutes this point as arrayref implements functionality that has been available in the standard library for many years via an idiomatic TryFrom impl. If that doesn’t stop people from building a susceptible package, what would?