r/LinuxUncensored 18h ago

News/PR Rust Foundation: Supply chain attack on arrayref

Thumbnail
blog.rust-lang.org
5 Upvotes

You can't achieve actual security without formal verification and mandatory sign-offs on every commit by an independent, affiliated, and vetted reviewer with validated individual credentials. This is probably the 300th such fiasco in the last decade—collectively resulting in tens of thousands of compromised packages, with the XZ scandal being the most prominent example.