In case you missed it, the spree of supply chain attacks visited Rust, hitting arrayref (245+ million downloads all time)
Our Threat Center Advisory went out to customers a while ago. I wasn't going to blog ... and then we saw the DPRK connection
đ°đĩđ¤đĻ
Everyone is tweeting out "use pnpm & set a minimumReleaseAge of 7 days"
but don't forget blockExoticSubdeps - which would also prevent the usage of a remote github reference here!
Wrote a companion to our GitHub Actions hardening guide: this one covers packages.
Get a clear rundown of your options: cooldowns, lockfiles, registry proxies, canaries, + more
Hopefully useful as a reference given the recent incidents!