> If I look at actual incidence involving memory safety issues compared to supply chain issues in general, it is the later which is much a higher risk to me.
Again, can you even just name a single supply chain attack that was *shipped* in Rust software? Against the thousands and thousands of known memory vulnerability bugs throughout time?
> And yes, there were successful supply chain attacks on Rust developers, even just recently: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on... despite this being a "solved" problem.
No, your linked blog post predates the brand-new min-age requirement. The minimum age would have prevented it, since it was detected by AI within an hour. If anything it supports my point.
Plus, as I already mentioned, that is a build.rs supply chain attack that targets developers, not shipped software.