Skip to content

Post about a change to the crates.io malware notification policy#1795

Merged
Turbo87 merged 5 commits intorust-lang:mainfrom
LawnGnome:end-of-routine-crate-announcements
Feb 13, 2026
Merged

Post about a change to the crates.io malware notification policy#1795
Turbo87 merged 5 commits intorust-lang:mainfrom
LawnGnome:end-of-routine-crate-announcements

Conversation

@LawnGnome
Copy link
Copy Markdown
Contributor

@LawnGnome LawnGnome commented Feb 11, 2026

We can't publish this until rustsec/advisory-db#2638 is merged and we have advisory numbers for three of the crates, so I'm opening this as a draft for now.

This also rolls in notifications about the last few malicious crates before the policy change.

More context: https://rust-lang.zulipchat.com/#narrow/channel/318791-t-crates-io/topic/how.20to.20announce.20takedowns.3F/near/563504478

Rendered

@djc
Copy link
Copy Markdown
Contributor

djc commented Feb 12, 2026

Is it useful to mention the RustSec advisory RSS feed as a method to stay informed about these kinds of things?

@LawnGnome
Copy link
Copy Markdown
Contributor Author

Is it useful to mention the RustSec advisory RSS feed as a method to stay informed about these kinds of things?

Definitely! I'll add a line, thanks.

@LawnGnome LawnGnome marked this pull request as ready for review February 12, 2026 18:11
@LawnGnome
Copy link
Copy Markdown
Contributor Author

This is ready for review (ping @rust-lang/crates-io in general, and @carols10cents in particular, since we were talking about this yesterday).

@djc
Copy link
Copy Markdown
Contributor

djc commented Feb 12, 2026

Appreciate the shout out!

Copy link
Copy Markdown
Member

@carols10cents carols10cents left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Other than the date, LGTM!

Comment thread content/crates.io-malicious-crate-update.md Outdated
@LawnGnome
Copy link
Copy Markdown
Contributor Author

Just waiting for rustsec/advisory-db#2642, then I'll push another update and we can merge this.

@Turbo87 Turbo87 enabled auto-merge February 13, 2026 17:50
@Turbo87 Turbo87 merged commit 6391836 into rust-lang:main Feb 13, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

5 participants