Skip to content

SECURITY: arrayref 0.3.10 is malicious #33

Description

@nebasuke

A heads up for anyone else wondering what the situation is with the latest crates being yanked.
0.3.10 is a compromised, malicious release containing a new runtime dep:  [dependencies.proc-macro1] = "1.0.107" which is a typosquat of proc-macro2.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions