Package manager typosquatting is not just for JS anymore 😉
https://blog.rust-lang.org/2022/05/10/malicious-crate-rustdecimal.html
@brion Do you know if any of these package repos are deploying some sort of fuzzy matching on new package names to flag possible clashes?
@cstanhope no idea :D but ... i hope so
@brion non distro package managers were a bad idea, convince otherwise.
This Mastodon instance is for people interested in technology. Discussions aren't limited to technology, because tech folks shouldn't be limited to technology either!
@brion Do you know if any of these package repos are deploying some sort of fuzzy matching on new package names to flag possible clashes?