andrewnez ("Andrew Nesbitt") wrote:
Fun new rabbit hole, finding all the -sys crates embedded within node/ruby/python packages, so you have C/C++ inside rust inside another package.
Then going and looking up vulns in those C/C++ projects in the sys crates to see how many sneaky vulns are being shipped via npm/gem/pypi.