I think this brings even more demand for the minimum Rust version feature. (https://github.com/rust-lang/rfcs/pull/2495 …) That makes it possible to defend against similar "config retro-interpretation" vulnerabilities in the future.
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
That's impossible to do pervasively, because new crates using the feature are published all the time, and not all crates that use it are even in http://crates.io , so the team couldn't know about them.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
That's not an effective mitigation as it would only cover crates published today, without addressing private projects or future crates. The only solutions we recommend are either to upgrade to a supported compiler or to apply the provided patches and build rustc yourself.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
`rustup update` :)
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.