Skip to content

Draft RustSec advisory #34

@ijackson

Description

@ijackson

Hi. Someone I know was recently surprised to discover some things cargo-husky had done on their system. On reflection, I concluded that the behaviour, while intentional, is something that a user who builds a depending package ought to be told about, via the RustSec advisory database.

So I have made a draft of such an advisory:
https://github.com/ijackson/rustsec-advisory-db/blob/cargo-husky/crates/cargo-husky/RUSTSEC-0000-0000.md
I haven't submitted it to RustSec yet because I wanted to give you a heads-up, and the opportunity to review my draft. Please let me know your thoughts.

I appreciate that this is rather a difficult situation. Thanks for your attention.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions