| ▲ | bcjdjsndon 3 hours ago | |||||||
> Who is funding this security audit? Are folks supposed to volunteer their free time? Same people who keep the whole rust project going, a lot of those are volunteers aren't they? Not mad to think they could do the same for core packages at least | ||||||||
| ▲ | aw1621107 3 hours ago | parent | next [-] | |||||||
> Same people who keep the whole rust project going, a lot of those are volunteers aren't they? Sure, but from my understanding the Rust project is generally "bottom-up" in that volunteers generally work on what they want to rather than submit their time into a pool for some kind of higher-level management to direct. | ||||||||
| ▲ | nicoburns 2 hours ago | parent | prev | next [-] | |||||||
The core packages (things like rand and regex) are pretty closely audited in practice (albeit it might not catch a credential compromise). This crate isn't one of them. | ||||||||
| ||||||||
| ▲ | mirashii 3 hours ago | parent | prev [-] | |||||||
It’s absolutely mad and extremely entitled to expect that a volunteer group of developers do an order of magnitude or more additional work for no additional pay or benefits to themselves. | ||||||||
| ||||||||