This user is scraping crates.io and squatting unclaimed dictionary words

This page summarizes the projects mentioned and recommended in the original post on /r/rust

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • crates.io

    The Rust package registry

  • As mentioned, attackers can create multiple accounts. I would suggest a few things here. (1) is monitoring - I would bet that 99.9999% or more users on crates.io produce fewer than a very small number of crates, like maybe 3? Flag those for review. (2) is working with github. crates.io uses github.com as its IDP - report these users to github.com so that they can assist with the issue. Microsoft is a rust sponsor, I guarantee there's at least one person at Github who is interested in helping here (talk to their platform abuse team).

  • Puts Debuggerer

    Ruby library for improved puts debugging, automatically displaying bonus useful information such as source line number and source code.

  • As mentioned, attackers can create multiple accounts. I would suggest a few things here. (1) is monitoring - I would bet that 99.9999% or more users on crates.io produce fewer than a very small number of crates, like maybe 3? Flag those for review. (2) is working with github. crates.io uses github.com as its IDP - report these users to github.com so that they can assist with the issue. Microsoft is a rust sponsor, I guarantee there's at least one person at Github who is interested in helping here (talk to their platform abuse team).

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • rfcs

    RFCs for changes to Rust

  • ktra

    Your Little Cargo Registry

  • Ktra

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts