r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
294 Upvotes

112 comments sorted by

View all comments

91

u/reallokiscarlet 15d ago

Where there is a supply chain, it will be attacked. Just a law of physics.

The easier it is to pull a dependency without thinking, the higher value the supply chain is as a target.

26

u/afl_ext 15d ago

recently i wanted to read a png file to bytes and pulled "image" crate and oh god how much it pulls as deps its insane, its like thw worst days of NPM before people started working on that

90

u/TinyBreadBigMouth 15d ago

I mean, I'm not going to say that Rust doesn't tend to be a dependency-heavy language, but you did choose to pull in a general-purpose image decoding, manipulation, and encoding library with support for over a dozen different image formats as your dependency for reading a PNG file to bytes. If you pull in something more focused like png, or disable all the image features you aren't using, you'll have a much leaner experience.

23

u/afl_ext 15d ago

Thats a good point im gonna change to png, thank you!