Rust library bugs in FFI or other unsafe code blocks can have severe consequences, even remote code execution.
It's great to see that there's now a site for announcing security bugs in the ecosystem:
Difftastic 0.71 is out! This is a polish release, still well worth upgrading:
* A ton of performance improvements, especially for nasty corner cases.
* Improved C++, Dockerfile, Haskell, JavaScript, Makefile, Perl, Ruby, Rust, Scala and TypeScript.
The literal 0xffu8 in Rust is pretty tricky to read without syntax highlighting. It looks like a plain hexadecimal value at first.
(Why not have syntax highlighting? Ironically I was debugging and improving VS Code's Rust highlighting.)
It's really satisfying fixing crashes in rust-analyzer. You can start from a panic message and dig until you've got a tiny Rust program that triggers the problem.
(It's usually an issue with incomplete source files breaking invariants.)