Rust: News

https://blog.rust-lang.org/2023/08/03/cve-2023-38497.html

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

5
0
https://github.com/rust-lang/rfcs/pull/3355

The Foundation is planning to hire a technical editor / project manager for somewhere between 6 and 9 months.

10
1