Edit: Yep: https://mozilla.github.io/cargo-vet/design-choice-faq.html#h...
None of the reasons given by Mozilla seem to justify the downgrade in security, especially since most can be worked around with crev which already employs secure and well-tested authentication schemes.
What also makes this situation peculiar to me is that it's being immediately rushed into Cargo proper instead of the usual way these tools are handled by the Cargo team (i.e. allowing multiple ideas to compete as third-party tools and maybe choosing one once a winner is clear). I understand the recent string of security issues might have played a role here, but I wouldn't expect their reaction to be steamrolling an inferior version of crev as a builtin tool.
I would really like to know what happened here.
Disclosure: I use neither tool, but I'm very interested in the security and health of the Rust ecosystem.