Supply Chain Thoughts

This page summarizes the projects mentioned and recommended in the original post on /r/rust

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • crates.io

    The Rust package registry

    Sorry, I mean no benefit over the proposal of doing this on the server and outright preventing the publish of a crate with a low edit distance. I also proposed that crates.io maintains an audit log of publishes that includes edit distance, which I think is similar to your suggestion ultimately.

  • Cargo

    The Rust package manager

    We might not need to reserve all typos. Soon cargo add will be in the stable release and we are hoping to have crates.io start suggesting it along with or in place of the Cargo.toml snippet. cargo-add could check for typos when you add a dependency. We could even check for registry squatting. If all else fails, we can check for security advisories when adding a crate.

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts