{
  "video_id": "reddit_1vtm22r",
  "channel_slug": "programming",
  "channel_handle": "r/programming",
  "title": "Supply chain attack on arrayref",
  "url": "https://www.reddit.com/r/programming/comments/1vtm22r/supply_chain_attack_on_arrayref/",
  "external_url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/",
  "upload_date": "20260820",
  "published_at": "2026-08-20T15:05:52+00:00",
  "transcript": "\n\n--- Top Comments ---\n\n\n[75 upvotes] Was only a question of time. Rust has the same mindset as Node/NPM.\n\nPS: for the screaming crowd: yes, anyone can get supply chain attacked. HOWEVER: \n\n* If you have a proper stdlib, chances are, you don't have a lot of dependencies\n* If you have less dependencies, the chance of supply chain attacks drops significantly\n* If you have well established dependencies like Spring, their security practices are very likely better than a rando off the internet\n\nWhat does that mean for Rust? They don't need to just work on the language, they need to provide a larger ecosystem as well. How they do it is up to them.\n\n[70 upvotes] Longest exposure time 107min. At least this one got caught quickly.",
  "transcript_chars": 731,
  "ingested_at": "2026-08-21T01:30:19.315491+00:00",
  "source": "reddit",
  "yt_meta": {
    "score": 111,
    "upvote_ratio": 0.98,
    "num_comments": 32,
    "author": "Successful_Bowl2564",
    "is_self": false
  }
}