Skip to content

Crate Owners Security Manual #45

@pinkforest

Description

@pinkforest

I was wondering what else we could do as a WG to help crate maintainers to keep their crates secure.

This was in combination with some governance stuff I had to sort out at cargo-geiger.

And I was thinking maybe documentation / best practice or "guidelines" could enable the maintainers to do the right things (tm)

It does need a catchy marketable name too! And it should be pleasant, fun and enjoyable to read/consume vs beating the morals.

It should be in story form so people can relate the importance best.

First I am wondering about the scope this thing could potentially cover -

Maybe

  • Thou Shall Not Roll Your Own Crypto
  • All the Badges You Can Eat in your README.md
  • Release Process repo & crates.io
  • Maintenance and handover
  • Dependabot / dependency monitoring and importance of it with stories
  • Unsafe Dark Arts
  • ..... ?

Also we should come up with a simple requirements type checklist to help crate maintainers to test themselves on the above

Every topic should enable the crate maintainer to automate from get-go that encourages good patterns without questions and friction that would deter adoption.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions