Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But how do we scale that to 1000 dependencies, and every one of their updates? What tools are there to help us, and does the community at large use them?

Use

    cargo install cargo-supply-chain
    cargo supply-chain --publishers
Run it for whatever you want to check, then have a lunch, it takes 10-30min.

It will list exactly how many organizations, and even individuals with publish rights are there. For turso there are 51 repositories, and 243 different individuals with publish rights.

Of course, this still doesn't group by github org and so on.





Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: