55
Could rust do with a crates.io alternative?
(programming.dev)
Welcome to the Rust community! This is a place to discuss about the Rust programming language.
Credits
Still makes you bound to github. Can't publish to crates.io without github.
What security guarantee does github have? I can create a new account right now with a random email, sign up for crates.io and type-squat a package.
Sure, but how do you discover the package? That's the other function of a registry. Also, I could easily just add another package as a submodule, but that's not the point.
I think the security guarantee is for the user and their credentials, not the community and trustworthiness of individuals.