Skip to content

Add capability to flatten dependency tree into a single directory for easier dependecy hack prevention #17380

Description

@adalfarus

Problem

Supply chain attacks are hard to prevent when each packages depends on three others and you end up with hundreds of dependencies you need to check, and then re-check after every update permissible by the dep filter of all the crates that are in your tree. Or you need to add all dependencies of all packages to your dependencies with locked versions, which is also hard. Especially because you also need to update your deps to get fixes for known vulnerabilities.

Proposed Solution

Basically the sub command:

"cargo flatten --depth x"

where all packages deeper in the dependency tree than x are flattened into one directory which can then be committed to version control. When updating the dependencies, this approach could also make it easier to spot hacked packages as their source is not longer opaque and changes are tracked.

Notes

Should be relatively easy to implement, just copy the checked out repos to e.g. ./flatten and overwrite them when updating. The whole dep checking doesn't need to change, it would just need to check the depth of a package and copy it over if its over x.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    C-feature-requestCategory: proposal for a feature. Before PR, ping rust-lang/cargo if this is not `Feature accepted`S-needs-infoStatus: Needs more info, such as a reproduction or more background for a feature request.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions