Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

typosquat: add suffix checks #7571

Merged
merged 1 commit into from
Nov 21, 2023
Merged

Commits on Nov 20, 2023

  1. typosquat: add suffix checks

    This extends our new typosquatting checks (see rust-lang#7206) to detect an
    attack vector we've seen more recently where a bad actor tries to squat
    an existing, popular crate by adding or removing a common suffix (such
    as `-rs` or `-sys`).
    
    The suffix list in the configuration has been taken _approximately_ from
    the most popular suffixes in the existing set of crates, with a small
    amount of human judgement involved on which ones are more likely to be
    abused based on recent incidents.
    LawnGnome committed Nov 20, 2023
    Configuration menu
    Copy the full SHA
    b6ce52d View commit details
    Browse the repository at this point in the history