plrust
plrust copied to clipboard
Integrating with existing code auditing tooling support?
It's worth examining possible usage of
- cargo vet for vetting arbitrary dependency trees
-
cargo geiger for checking
unsafecode - cargo supply chain
- cargo auditable
-
cargo audit which is really more like
cargo cvecheck, but I digress... -
miri for evaluating the
unsafecode that we will have to depend on anyways, viacargo mirior other means - kani for model checking
and even if none of these are directly usable by the PL/Rust build tooling, or cannot be used in continuous integration and testing scenarios, to provide possible advisories regarding using them in concert.