• An update to the malicious crate notification policy (Rust Blog)

    From LWN.net@86:200/23 to All on Thu Feb 19 06:40:09 2026

    Adam Harvey, on behalf of the crates.io
    team has published a blog
    post to inform users of a change in their practice of publishing
    information about malicious Rust crates:

    The crates.io team will no longer publish a blog post each time a
    malicious crate is detected or reported. In the vast majority of cases
    to date, these notifications have involved crates that have no
    evidence of real world usage, and we feel that publishing these blog
    posts is generating noise, rather than signal.

    We will always publish a RustSec
    advisory when a crate is removed for containing malware. You can
    subscribe to the RustSec
    advisory RSS feed to receive updates.

    Crates that contain malware and are seeing real usage or
    exploitation will still get both a blog post and a RustSec
    advisory. We may also notify via additional communication channels
    (such as social media) if we feel it is warranted.

    https://lwn.net/Articles/1059338/
    --- SBBSecho 3.34-Linux
    * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (86:200/23)