EFForg/rayhunter

Question on Dependency Security / Supply Chain Security

開放

#195 建立於 2025年3月25日

 (9 則留言) (1 個反應) (0 位負責人)Rust (465 個分叉)github user discovery
documentationenhancementhelp wantedquestion

倉庫指標

星標
 (5,620 顆星)
PR 合併指標
 (平均合併 5天 12小時) (30 天內合併 6 個 PR)

描述

Hey, thank you for providing yet another nice tool for making the world a bit safer!

Since this tool is written in Rust and has quite a few direct and transitive dependencies, I was wondering if you could share some insight on ensuring you don't pull in malware by accident. This is a thing I'm struggling with a bit whenever I see some software is written in Rust or whenever I inherit Rust code to work on.

I know this is not an issue and I'm sorry for adding triage overhead, but seems to be the most appropriate place to ask such a question... well apart from a mailing list :D

Thank you, Jan

貢獻者指南