19-08-2023 21:34 via developers.slashdot.org

Rust Users Push Back as Popular 'Serde' Project Ships Precompiled Binaries

"Serde, a popular Rust (de)serialization project, has decided to ship its serde_derive macro as a precompiled binary," reports Bleeping Computer.
"The move has generated a fair amount of push back among developers who worry about its future legal and technical implications, along with a potential for supply chain attacks, should the maintainer account publishing these binaries be compromised."According to the Rust package registry, crates.io, serde has been downloaded over 196 million times over
Read more »