Mostly because 99% of developers knows nothing about supply chain attacks and leftpad blew up.
Both npm and rust should force 2FA. Thankfully, crates.io forces github SSO, and github will eventually force 2FA.
Ouch. That must be difficult for any Rust package maintainers whose GitHub accounts were deleted a few months ago due to the Russian war sanctions.
Mostly because 99% of developers knows nothing about supply chain attacks and leftpad blew up.
Both npm and rust should force 2FA. Thankfully, crates.io forces github SSO, and github will eventually force 2FA.