> Congratulations to Rust for its first (but not its last) supply-chain attack this week! They join a growing club of broken-by-design package managers which publish packages uploaded by vendors directly, with no review step, and ship those packages directly to users with no further scrutiny. [1]
And in the post where he's complaining about GoModuleProxy, he manages to self-righteously insult the entire Go team for no good reason:
> I will say that if I was in their position, and my service was mistakenly sending an excessive amount of traffic to someone else, I would make it my first priority to fix it. But I suppose no one will get promoted for prioritizing that at Google. [2]
[1] https://drewdevault.com/2022/05/12/Supply-chain-when-will-we...
[2] https://drewdevault.com/2022/05/25/Google-has-been-DDoSing-s...