Article 70Y6X Forking confusing: Vulnerable Rust crate exposes uv Python packager

Forking confusing: Vulnerable Rust crate exposes uv Python packager

by
from The Register on (#70Y6X)
Story ImageForks of forks of forks, but which ones are patched?

A vulnerability in the popular Rust crate async-tar has affected the fast uv Python package manager, which uses a forked version that's now patched - but the most widely downloaded version remains unfixed....

External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title The Register
Feed Link https://www.theregister.com/
Feed Copyright Copyright © 2025, Situation Publishing
Reply 0 comments