{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreiezv4uoe4bv6wpgr5blxyjxmnetw7h2bcczhcrbg62xzxr6l5chou",
"uri": "at://did:plc:ivbknywyskln22er3nkssdhl/app.bsky.feed.post/3mja3klsmzui2"
},
"path": "/t/build-security/24166#post_9",
"publishedAt": "2026-04-11T07:53:30.000Z",
"site": "https://internals.rust-lang.org",
"textContent": "The exposed name doesn’t work for transitive deps. First thought is that I would expect it to be either with a version specifier (so you can choose whether you want to have to re-audit after updates) or a checksum (of the build.rs and its imports). But both of those are complicated by the fact it may have build-dependencies though .",
"title": "Build Security"
}