Skip to content
This repository was archived by the owner on Jan 16, 2025. It is now read-only.

Commit abb0fe3

Browse files
Publish Crates.io Guest Blog (#413)
* Updated 1 file via CloudCannon. * Added 1 file via CloudCannon. * Updated 1 file via CloudCannon. --------- Co-authored-by: Gracie Gregory <[email protected]> 46e0e62
1 parent 6d74354 commit abb0fe3

File tree

22 files changed

+536
-278
lines changed

22 files changed

+536
-278
lines changed

feed/feed.json

Lines changed: 7 additions & 1 deletion
Large diffs are not rendered by default.

feed/feed.xml

Lines changed: 48 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,21 +5,66 @@
55

66
<link href="https://foundation.rust-lang.org/feed/feed.xml" rel="self"/>
77
<link href="https://foundation.rust-lang.org"/>
8-
<updated>2023-06-14T12:30:00Z</updated>
8+
<updated>2023-06-15T14:00:00Z</updated>
99
<id>https://foundation.rust-lang.org/</id>
1010
<author>
1111
<name>The Rust Foundation</name>
1212
<email>[email protected]</email>
1313
</author>
1414

15+
<entry>
16+
<title>A Note on Data Retention &amp; Data Privacy Standards From the crates.io Team</title>
17+
<link href="https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/"/>
18+
<updated>2023-06-15T14:00:00Z</updated>
19+
<id>https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/</id>
20+
<content type="html">&lt;p&gt;On May 24th, &lt;a href=&quot;https://blog.pypi.org/posts/2023-05-24-pypi-was-subpoenaed/&quot;&gt;&lt;u&gt;PyPI announced that they had received multiple subpoenas&lt;/u&gt;&lt;/a&gt; from the United States Department of Justice requesting PyPI user data. Since then, members of the Rust community have reached out to ask if any similar requests have been received by the &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team, and have inquired about the policies of &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt;, the Rust Project, and the Rust Foundation should such a request be received.&lt;/p&gt;
21+
&lt;h3 id=&quot;the-crates.io-team-members-and-the-rust-foundation-can-confirm-that-neither-group-has-received-requests-for-private-crates.io-user-data-as-of-this-post-(june-15%2C-2023).&quot;&gt;&lt;strong&gt;The &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team members and the Rust Foundation can confirm that neither group has received requests for private &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; user data as of this post (June 15, 2023).&lt;/strong&gt; &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/#the-crates.io-team-members-and-the-rust-foundation-can-confirm-that-neither-group-has-received-requests-for-private-crates.io-user-data-as-of-this-post-(june-15%2C-2023).&quot;&gt;#&lt;/a&gt;&lt;/h3&gt;
22+
&lt;p&gt;The &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team intends to work with the Rust Foundation and legal counsel to add an amendment to the &lt;a href=&quot;https://foundation.rust-lang.org/policies/privacy-policy/&quot;&gt;&lt;u&gt;existing Rust privacy policy governing crates.io and other official Rust sites and applications&lt;/u&gt;&lt;/a&gt;. This amendment will specify the process that will be followed in the event such a request is received from law enforcement or a government agency. &lt;/p&gt;
23+
&lt;h3 id=&quot;while-we-are-unable-to-provide-specifics-on-this-amendment-until-we-have-had-more-time-to-confer-with-legal-counsel%2C-our-guiding-principles-in-the-interim-will-be-as-follows%3A&quot;&gt;While we are unable to provide specifics on this amendment until we have had more time to confer with legal counsel, our guiding principles in the interim will be as follows: &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/#while-we-are-unable-to-provide-specifics-on-this-amendment-until-we-have-had-more-time-to-confer-with-legal-counsel%2C-our-guiding-principles-in-the-interim-will-be-as-follows%3A&quot;&gt;#&lt;/a&gt;&lt;/h3&gt;
24+
&lt;ol&gt;
25+
&lt;li&gt;We will only respond to legal requests made to the Rust Foundation concerning &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; that are complete, correct, and legally-binding.&lt;/li&gt;
26+
&lt;li&gt;The &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team will provide only the minimum data required by the request.&lt;/li&gt;
27+
&lt;li&gt;The &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team will communicate the nature of the request and what was provided to the maximum extent allowed by the request and law, while respecting the anonymity of those involved.&lt;/li&gt;
28+
&lt;li&gt;If the request allows us to notify the subject(s) of the request and we have contact details for the subject(s), we will notify them directly of what data was provided. We will also consult with our legal counsel about the potential ways we could publicly, and anonymously, report any legally-binding requests for data we might receive in the future.&lt;/li&gt;
29+
&lt;/ol&gt;
30+
&lt;p&gt;The &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team would also like to commend PyPI and the Python Software Foundation for the way they handled this request. We will seek to emulate their approach as closely as we can should we ever find ourselves in this position. &lt;/p&gt;
31+
&lt;h2 id=&quot;our-existing-data-retention-and-privacy-policy&quot;&gt;Our Existing Data-Retention and Privacy Policy &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/#our-existing-data-retention-and-privacy-policy&quot;&gt;#&lt;/a&gt;&lt;/h2&gt;
32+
&lt;p&gt;Below, you’ll find a summary of the existing privacy policy followed by the Rust Foundation, &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt;, and associated Rust Project services. While this information is discoverable via the Rust Foundation privacy policy, we are sharing it here to reinforce the limited data we collect and the strict parameters around its retention:&lt;/p&gt;
33+
&lt;h3 id=&quot;crates.io-receives-the-following-data-from-its-users-upon-log-in%3A&quot;&gt;&lt;strong&gt;&lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; Receives the Following Data From its Users Upon Log In: &lt;/strong&gt; &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/#crates.io-receives-the-following-data-from-its-users-upon-log-in%3A&quot;&gt;#&lt;/a&gt;&lt;/h3&gt;
34+
&lt;ul&gt;
35+
&lt;li&gt;As a GitHub account is required for log-in, &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; receives users’ GitHub usernames, avatars, and any email addresses publicly listed in their GitHub public profile. &lt;/li&gt;
36+
&lt;li&gt;As a verified email address is required to publish a crate, we receive any public email address associated with your GitHub account and any email a user enters directly into &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt;. We only use your email address to contact you about your account.&lt;/li&gt;
37+
&lt;li&gt;In order to associate user accounts with the appropriate organizations and teams, we also collect users’ organization memberships and the teams within them from GitHub &lt;/li&gt;
38+
&lt;li&gt;When you visit &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; or interact with &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; using Cargo, we receive your IP address, user-agent header, and request path as part of our standard server logs. Log entries for some authenticated requests, such as publishing a crate, also contain your &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; account. These logs are stored for 1 year.&lt;/li&gt;
39+
&lt;li&gt;Upon visiting &lt;a href=&quot;http://static.crates.io/&quot;&gt;static.crates.io&lt;/a&gt; (where the crate files that Cargo downloads are hosted), we receive your IP address, user-agent header, referer header, and request path as part of our standard server logs. These logs are stored for 1 year.  Cargo downloads are not associated with your &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; username, as we do not store that information.&lt;/li&gt;
40+
&lt;li&gt;All crates on &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; are public, including the list of crate owners’ usernames and the crate upload date. Anyone may view or download a crate’s contents. Because of the public nature of &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt;, any personal data you might include in a Cargo.toml file uploaded to a crate is publicly available. &lt;/li&gt;
41+
&lt;li&gt;Due to its public nature, be aware if you include any private information in a crate that information may be indexed by search engines or used by third parties. Sensitive information should not be included in a crate file.&lt;/li&gt;
42+
&lt;/ul&gt;
43+
&lt;h3 id=&quot;rust-foundation-data-retention-policies%3A&quot;&gt;&lt;strong&gt;Rust Foundation Data-Retention Policies: &lt;/strong&gt; &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/#rust-foundation-data-retention-policies%3A&quot;&gt;#&lt;/a&gt;&lt;/h3&gt;
44+
&lt;ul&gt;
45+
&lt;li&gt;The Rust Foundation retains personal data only for as long as is necessary, or as needed to provide users with the Foundation’s services.&lt;/li&gt;
46+
&lt;li&gt;If a user wishes for their personal information to be removed from a Foundation service, they may request deletion of that information.&lt;/li&gt;
47+
&lt;li&gt;The Rust Foundation will retain and use user information only to the extent necessary to comply with our legal obligations.&lt;/li&gt;
48+
&lt;/ul&gt;
49+
&lt;p&gt;&lt;a href=&quot;https://foundation.rust-lang.org/policies/privacy-policy/#data-retention&quot;&gt;&lt;u&gt;Click here&lt;/u&gt;&lt;/a&gt; to read the full language of the policies listed above. &lt;/p&gt;
50+
&lt;hr /&gt;
51+
&lt;h2 id=&quot;summary&quot;&gt;Summary &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/#summary&quot;&gt;#&lt;/a&gt;&lt;/h2&gt;
52+
&lt;p&gt;The &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team will be meeting with the Rust Foundation and legal counsel to update and expand our shared data-retention policy. Our goal will be to add an amendment on how we would operate if a legally-binding request for data is issued and determine opportunities to minimize the level of data we retain without compromising the management of the Rust infrastructure. If you have feedback or specific concerns about the types of private user data we retain that might be available to a legally binding request, please email that feedback to &lt;a href=&quot;mailto:[email protected]&quot;&gt;&lt;u&gt;[email protected]&lt;/u&gt;&lt;/a&gt; and/or &lt;a href=&quot;mailto:[email protected]&quot;&gt;[email protected]&lt;/a&gt;.&lt;/p&gt;
53+
&lt;p&gt;We will post updates on our progress in the &lt;a href=&quot;https://rust-lang.zulipchat.com/#narrow/stream/335408-foundation/topic/Data-Retention.20Policy.20Amendment.20Updates&quot;&gt;&lt;u&gt;&amp;quot;Data-Retention Policy Amendment Updates&amp;quot; topic in the public foundation Zulip stream&lt;/u&gt;&lt;/a&gt;. This work will likely take multiple months of coordination between all groups.&lt;/p&gt;
54+
&lt;p&gt;The existing Rust Foundation and &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; privacy and data-retention policy can be found &lt;a href=&quot;https://foundation.rust-lang.org/policies/privacy-policy/&quot;&gt;&lt;u&gt;here&lt;/u&gt;&lt;/a&gt;. &lt;/p&gt;
55+
&lt;p&gt;Signed,&lt;/p&gt;
56+
&lt;p&gt;The &lt;a href=&quot;http://crates.io/&quot;&gt;crates.io&lt;/a&gt; team (in collaboration with the Rust Foundation)&lt;/p&gt;
57+
</content>
58+
</entry>
59+
1560
<entry>
1661
<title>Rust Foundation to Host Inaugural “Rust Global” Event at WasmCon 2023</title>
1762
<link href="https://foundation.rust-lang.org/news/rust-foundation-to-host-inaugural-rust-global-event-at-wasmcon-2023/"/>
1863
<updated>2023-06-14T12:30:00Z</updated>
1964
<id>https://foundation.rust-lang.org/news/rust-foundation-to-host-inaugural-rust-global-event-at-wasmcon-2023/</id>
20-
<content type="html">&lt;p&gt;&lt;a href=&quot;https://foundation.rust-lang.org/&quot;&gt;The Rust Foundation&lt;/a&gt; is pleased to present &lt;a href=&quot;https://events.linuxfoundation.org/rust-global/&quot;&gt;Rust Global&lt;/a&gt; – a new event focused on the future of the Rust programming language. The first instance will taking place as a half-day event within &lt;a target=&quot;_blank&quot; href=&quot;https://events.linuxfoundation.org/wasmcon/&quot;&gt;WasmCon&lt;/a&gt; on September 6, 2023. &lt;/p&gt;
65+
<content type="html">&lt;p&gt;&lt;a href=&quot;https://foundation.rust-lang.org/&quot;&gt;The Rust Foundation&lt;/a&gt; is pleased to present &lt;a href=&quot;https://events.linuxfoundation.org/rust-global/&quot;&gt;Rust Global&lt;/a&gt; – a new event focused on the future of the Rust programming language. The first instance will be taking place as a half-day event within &lt;a target=&quot;_blank&quot; href=&quot;https://events.linuxfoundation.org/wasmcon/&quot;&gt;WasmCon&lt;/a&gt; on September 6, 2023 in Bellevue, Washington in the United States. &lt;/p&gt;
2166
&lt;p&gt;The first Rust Global will feature a mix of talks (sourced from the &lt;a href=&quot;https://events.linuxfoundation.org/wasmcon/program/cfp/#suggested-topics&quot;&gt;&lt;u&gt;WasmCon CFP&lt;/u&gt;&lt;/a&gt;) and networking opportunities. Content will focus on the intersection of Rust and WebAssembly, Rust case studies for business innovation, and valuable Rust adoption stories. &lt;/p&gt;
22-
&lt;p&gt;The Rust Foundation believes that a strong relationship between global leaders and the Rust community is essential as we look toward the future of cybersecurity, business, sustainability, and technological innovation where Rust will lend tremendous value. We are excited to help drive collaboration and enterprise in Rust through Rust Global at WasmCon 2023. &lt;/p&gt;
67+
&lt;p&gt;The Rust Foundation believes that a strong relationship between global leaders and the Rust community is essential as we look toward the future of cybersecurity, business, sustainability, and technological innovation where Rust will lend tremendous value. We are excited to help drive collaboration and enterprise in Rust through Rust Global at WasmCon 2023.&lt;/p&gt;
2368
&lt;p&gt;This event will be the first of many independent and co-located Rust Foundation events around the world to provide opportunities for Rust adopters, advocates, and enthusiasts to learn, share, and network. &lt;/p&gt;
2469
&lt;h3 id=&quot;&quot;&gt; &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/rust-foundation-to-host-inaugural-rust-global-event-at-wasmcon-2023/#&quot;&gt;#&lt;/a&gt;&lt;/h3&gt;
2570
&lt;h2 id=&quot;join-us-at-rust-global!&quot;&gt;Join us at Rust Global! &lt;a class=&quot;direct-link&quot; href=&quot;https://foundation.rust-lang.org/news/rust-foundation-to-host-inaugural-rust-global-event-at-wasmcon-2023/#join-us-at-rust-global!&quot;&gt;#&lt;/a&gt;&lt;/h2&gt;

index.html

Lines changed: 8 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,14 @@ <h1>News</h1>
6969

7070

7171

72-
<ol class="postlist" style="counter-reset: start-from 95">
72+
<ol class="postlist" style="counter-reset: start-from 96">
73+
74+
<li class="postlist-item">
75+
<a href="/news/a-note-on-data-retention-data-privacy-standards-from-the-crates-io-team/" class="postlist-link">A Note on Data Retention &amp; Data Privacy Standards From the crates.io Team</a>
76+
<time class="postlist-date" datetime="2023-06-15">15 Jun 2023</time>
77+
78+
<a href="/tags/guest blog series/" class="post-tag">guest blog series</a>
79+
</li>
7380

7481
<li class="postlist-item">
7582
<a href="/news/rust-foundation-to-host-inaugural-rust-global-event-at-wasmcon-2023/" class="postlist-link">Rust Foundation to Host Inaugural “Rust Global” Event at WasmCon 2023</a>
@@ -88,14 +95,6 @@ <h1>News</h1>
8895
<a href="/tags/programs/" class="post-tag">programs</a>
8996
</li>
9097

91-
<li class="postlist-item">
92-
<a href="/news/member-spotlight-traverse-research/" class="postlist-link">Member Spotlight: Traverse Research</a>
93-
<time class="postlist-date" datetime="2023-06-08">08 Jun 2023</time>
94-
95-
<a href="/tags/announcement/" class="post-tag">announcement</a>
96-
<a href="/tags/member spotlight/" class="post-tag">member spotlight</a>
97-
</li>
98-
9998
</ol>
10099

101100

0 commit comments

Comments
 (0)