rust-secure-code / wg

Coordination repository for the Secure Code Working Group
149 stars 10 forks source link

Community driven crates registry reflector #42

Open pinkforest opened 2 years ago

pinkforest commented 2 years ago

Just a wild idea

Would there be an interest of community "hardened" or "moderated" crates.io [registeries] reflector source that essentially filters to cargo automatically by-community-input on crates that are available to cargo via it's index ?

Essentially this would combine several tools - we could use registry hostname identifier which set of "exclusions" are to be used via the reflection.

NOTE: I am not sure yet whether "private" community registry would work properly with the current cargo as I haven't tested doing this but there is a flag and [registry] - However even without current support it would be nice to discuss the prospect / benefits / cons

Use-Cases

Logistics

Refs

pinkforest commented 2 years ago

@Shnatsel - would love your feedback on this :unicorn: