You must log in or register to comment.
The title seems like a stupid attack on open source… Because closed source abandonware is not a security issue??
At least open source projects can be forked and updated, a closed source system would leave you with only the option of choosing between the software or security.
Does this affect GNU tar, or Busybox tar, or BSD tar?
Honestly, cargo could flag crates with known CVEs, be a better package manager.
The Rust ier the container the more secure?



