Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
the8472
34 days ago
|
parent
|
context
|
favorite
| on:
Shai-Hulud malware attack: Tinycolor and over 40 N...
lib crates have been checking in their Cargo.lock for a while now.
https://github.com/rust-lang/cargo/pull/12382
Liskni_si
34 days ago
[–]
That Cargo.lock will only be used for the library's own CI though (and also for development if you git clone it). It will not be used by downstream dependencies at all.
Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
https://github.com/rust-lang/cargo/pull/12382