Using the build system (and potentially the compiler) to insert malicious backdoors is far from a new idea, and I don't see why this example would the only case.
Using the build system (and potentially the compiler) to insert malicious backdoors is far from a new idea, and I don't see why this example would the only case.
So has C++ in the past although there seems to be a push for a more batteries included approach recently.
> There's a strong culture as well of minimizing a project's dependencies in Rust.
This doesn't match what anyone can observe by looking at dependencies of Rust projects.
It would not have happened in any modern language. It probably wouldn't have even happened in a Vistual Studio C-project for windows either.
It would. pip for example installs from tarballs uploaded to PyPi, not from a git repository.
But in this case we are talking about people (distro packagers) manually downloading the source and building it which is not quite the same thing.
Distro-provided python packages don't use pip however, at least afaik.