• FizzyOrange@programming.dev
    link
    fedilink
    arrow-up
    3
    ·
    4 hours ago

    Yeah unfortunately these numbers don’t really allow any conclusions to be drawn at all.

    Also they’re not really related to supply chain security which is more about deliberate subterfuge. I think the interesting stat there would be how many authors are being trusted typically for each crate.

    • MoSal@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      4 hours ago

      I have the feeling that this wasn’t even done properly (e.g. checking default versions only). Using downloads alone is also not a good filter.

      I may give this some time tomorrow and provide my own numbers.