Mastodon Feed: Post

Mastodon Feed

andrewnez ("Andrew Nesbitt") wrote:

Fun new rabbit hole, finding all the -sys crates embedded within node/ruby/python packages, so you have C/C++ inside rust inside another package.

Then going and looking up vulns in those C/C++ projects in the sys crates to see how many sneaky vulns are being shipped via npm/gem/pypi.