mozilla / cargo-vet

supply-chain security for Rust
Apache License 2.0
651 stars 43 forks source link

Audit cool_faces crate #564

Closed robjtede closed 10 months ago

bholley commented 10 months ago

I apologize, but we can't accept externally-contributed audits into our set, Would be awesome if actix were to deploy its own set though, and we'd happily include it in the registry.

robjtede commented 10 months ago

Hey. That's fine, I maybe missed in the documentation exactly how to "contribute" audits.

bholley commented 10 months ago

They way to contribute audits is to submit them to an instance for an organization you're involved with. That allows anyone to pull in your audits if they're willing to trust your organization. This is somewhat covered in the overview as well as the documentation on curating an audit set.

robjtede commented 10 months ago

Appreciate the links for future reference.

I'll be honest, this PR more or less came out of a joke at EuroRust, so thanks for taking the time to respond. 👍