mozilla / cargo-vet

supply-chain security for Rust
Apache License 2.0
621 stars 43 forks source link

supply-chain vs dependencies #606

Open pinkforest opened 3 months ago

pinkforest commented 3 months ago

Thank you for the efforts and the improvement over the current model - I have a feature wish re: wording

supply-chain is a misnomer and it makes a lot of people unhappy - I'm myself quilty of advancing this paradigm -

Can we rename it ? to something that reflects the true nature of these valuable & auditable components.

Getting the terminlogy IMO would be essential for humanised approach and to educate the ecosystem re: expectations.

Also it would be great if there is some component e.g. FUNDING that could be directed via monetary to help fix bugs.

Prior art

Thanks for the consideration!