- cross-posted to:
- cybersecurity@lemmy.capebreton.social
- cross-posted to:
- cybersecurity@lemmy.capebreton.social
Yay. My first ad-masquerading-as-a-genuine-post experience on Lemmy!
Thus, we’ve developed a cargo extension that transparently queries the Phylum API for information about a package before it’s allowed to build.
Only our* malware-like behaviour is blessed. Because it’s a feature. And research-based. And security-oriented. And commercial! We told you about it beforehand and sold you the idea.
* Assuming the malware discovered is not theirs too.
Thanks for sharing. Very nice writeup.
Another way to mitigate type squatting would be namespacing crates. Much easier to verify who owns the package and related packages
Doesn’t really help: what if you typo the namespace instead? Same exact issue. Namespaces are useful for other things though, but not security.