rust-secure-code / safety-dance

Auditing crates for unsafe code which can be safely replaced
Apache License 2.0
536 stars 10 forks source link

`cargo crev` ID list #31

Open Lokathor opened 5 years ago

Lokathor commented 5 years ago

We might care to store a list of cargo crev URLs in a markdown file so that people can discover IDs more easily.

We don't even need to specifically endorse one user or another, people can decide for themselves who to trust, we just need to make it more visible.

danielhenrymantilla commented 5 years ago

Agreed. I haven't set up cargo crev for myself yet, but I know I would greatly appreciate having a list of ids, especially for the people in safety dance.

Shnatsel commented 5 years ago

Discover what reviewers are even available is definitely needed, but I feel this is more of a work item for cargo-crev itself than for safety-dance. Please open an issue at https://github.com/crev-dev/cargo-crev/issues

Shnatsel commented 4 years ago

Hot take: just put your crev IDs here. This will provide the discoverability if anyone is actively looking, and will not look too much like an endorsement.

tarcieri commented 4 years ago

Yes please, document them somewhere (this thread seems like a great place) and then we can figure out how to do a better integration.

Lokathor commented 4 years ago

Post the git urls for your crev info here and I'll edit them into the opening post as I have time.

dpc commented 4 years ago

We have a list of active proof repositories here: https://github.com/crev-dev/cargo-crev/wiki/List-of-Proof-Repositories . Also - as long as you cross-trust your IDs, any person that trust any of you, will quite easily download reviews from all others with cargo crev repo fetch trusted.