logoalt Hacker News

lostglasstoday at 2:05 AM3 repliesview on HN

To be honest Rust has the exact same supply chain attack pattern - it's just newer and more maintained at the moment. Give it a decade.


Replies

marcosdumaytoday at 4:09 AM

Programs in Rust (or almost every other language) normally have fewer dependencies by 2 or 3 orders of magnitude.

And that number tends to reduce even more when the ecosystem matures.

slopinthebagtoday at 4:08 AM

Supply chain attacks are available to every language and framework that uses dependencies or modules you don’t control.

nothinkjustaitoday at 2:07 AM

Rust doesn’t have post install scripts

show 4 replies