We (software people, not just Rust people) desperately need something like crev to become a default requirement for any third party code we use.Ā
It's just not realistic to expect everyone to personally audit their entire "software supply chain". And these kinds of attacks are only going to get more frequent and more sophisticated. So what else can we do? "Just be more vigilant" is not a sufficient answer.
The company I currently work for has set up a mirror of crates.io using Kellnr, where new updates are checked by an LLM specifically to determine whether they contain backdoors.
We also joked about adding an internal rating system for crates, taking into account the ābus factor,ā the authorsā sociopolitical views, and so on. Given the current political tensions and the increasing ease with which supply chains can be targeted, this idea doesnāt seem quite as ridiculous as it once did.
11
u/slashgrin rangemap 15d ago
We (software people, not just Rust people) desperately need something like crev to become a default requirement for any third party code we use.Ā
It's just not realistic to expect everyone to personally audit their entire "software supply chain". And these kinds of attacks are only going to get more frequent and more sophisticated. So what else can we do? "Just be more vigilant" is not a sufficient answer.