Today at work I did some end of the year house keeping with our dependencies and tried to enable cargo deny's build.ban.interpreted feature, which warns about scripts in your build/dev dependencies. Well it did warn and it did warn a lot. So I spend a day to open nearly 50 PR's to our dependencies to exclude various scripts from the published packages. Some of them are already merged, thanks to the maintainers there. The others hopefully land soon.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.weiznich.de/users/weiznich/statuses/115729957225141333 on your instance and quote it. (Note that quoting is not supported in Mastodon.)