Was only a question of time. Rust has the same mindset as Node/NPM.
PS: for the screaming crowd: yes, anyone can get supply chain attacked. HOWEVER:
If you have a proper stdlib, chances are, you don't have a lot of dependencies
If you have less dependencies, the chance of supply chain attacks drops significantly
If you have well established dependencies like Spring, their security practices are very likely better than a rando off the internet
What does that mean for Rust? They don't need to just work on the language, they need to provide a larger ecosystem as well. How they do it is up to them.
It also has flags like --offline, and --frozen, which means --locked --offline, so it's possible to nerf at least simple "download & execute something in the build file" attacks, though like the other commenter says, the programmer's editor may be set up to run the offending code.
Of course, but there's a difference in getting owned instantly on install and having to execute something first. Namely that in theory you have time to inspect the package first.
But as others have said, the build.rs basically owns you at installation time
119
u/piesou 12d ago edited 12d ago
Was only a question of time. Rust has the same mindset as Node/NPM.
PS: for the screaming crowd: yes, anyone can get supply chain attacked. HOWEVER:
What does that mean for Rust? They don't need to just work on the language, they need to provide a larger ecosystem as well. How they do it is up to them.