mimblewimble/grin

Limit exposure to dependencies weaknesses

オープン

#2,026 opened on 2018/11/27

 (5 件のコメント) (1 件のリアクション) (0 人の担当者)Rust (991 件のフォーク)batch import
good first issuehelp wantedtask

Repository metrics

Stars
 (4,876 個のスター)
PR merge metrics
 (PR metrics pending)

説明

I think we've all had this in mind for quite a while but this was a direct reminder (widely used npm package with newly injected malicious code):

https://github.com/dominictarr/event-stream/issues/116

I don't think we should worry about auditing every single of our dependencies and Rust does a good job at protecting us from some of these attacks. At this stage I'm also not too worried about crates.io getting hacked. But I do think we should at least make sure every single of our dependency is pinned to a specific version.

コントリビューターガイド