2024 shone an even brighter spotlight on the issue of supply chain security. Understanding the dependencies that we build on top of is crucial when building software that is both secure and trustworthy.In this talk, I'll discuss the tools and techniques that are available to Rustaceans to understand their dependencies, evaluate them both from security and sustainability perspectives, and make informed decisions when building with Rust. I'll also touch on work that is taking place — across many organisations, including the Rust project itself, the Rust Foundation, OpenSSF, and the broader FOSS ecosystem — that is helping here, both for Rust specifically and more broadly for all users of FOSS.

Comments

Please login to leave a comment