A dependency update can change what your program is allowed to do
A capsec diff of two published Rust crate versions shows why dependency review should include newly reachable filesystem, network, process, and FFI behavior.
5 entries exploring this thread.
A capsec diff of two published Rust crate versions shows why dependency review should include newly reachable filesystem, network, process, and FFI behavior.
How capsec makes filesystem and network authority visible in Rust types, what the compiler rejects, and where audit must take over.
Why executable claims need retained counterexamples, distinct failure states, and a gate that distrusts the confidence of its operator.
How auths-proof turns layer direction, offline verification, deterministic CBOR, and protocol bounds into executable repository checks.
What an honest formal map contributes to an open mathematical problem—and why preserving the red nodes is part of the result.