Skip to content

SECURITY: arrayref 0.3.10 is malicious #33

Description

@nebasuke

A heads up for anyone else wondering what the situation is with the latest crates being yanked.
0.3.10 is a compromised, malicious release containing a new runtime dep:  [dependencies.proc-macro1] = "1.0.107" which is a typosquat of proc-macro2.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions