Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
eslaught
36 days ago
|
parent
|
context
|
favorite
| on:
Malicious Rust crate Arrayref runs a build-time pa...
Why not? Cargo.lock includes the transitive dependencies, and Cargo itself reports everything that changes when you do an upgrade. Those are version changes, not code diffs, but it seems entirely tractable.
kmeisthax
36 days ago
[–]
I specifically meant a tool that shows code diffs for transitive dependencies.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: