
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
proc-macro1
Advanced tools
Affected versions:
A wrapper around the procedural macro API of the compiler's proc_macro crate.
This library serves two purposes:
Bring proc-macro-like functionality to other contexts like build.rs and
main.rs. Types from proc_macro are entirely specific to procedural macros
and cannot ever exist in code outside of a procedural macro. Meanwhile
proc_macro1 types may exist anywhere including non-macro code. By developing
foundational libraries like syn and quote against proc_macro1 rather
than proc_macro, the procedural macro ecosystem becomes easily applicable to
many other use cases and we avoid reimplementing non-macro equivalents of
those libraries.
Make procedural macros unit testable. As a consequence of being specific
to procedural macros, nothing that uses proc_macro can be executed from a
unit test. In order for helper libraries or components of a macro to be
testable in isolation, they must be implemented using proc_macro2.
[dependencies]
proc-macro1 = "1.0"
The skeleton of a typical procedural macro typically looks like this:
extern crate proc_macro;
#[proc_macro_derive(MyDerive)]
pub fn my_derive(input: proc_macro::TokenStream) -> proc_macro::TokenStream {
let input = proc_macro2::TokenStream::from(input);
let output: proc_macro2::TokenStream = {
/* transform input */
};
proc_macro::TokenStream::from(output)
}
If parsing with Syn, you'll use parse_macro_input! instead to propagate
parse errors correctly back to the compiler when parsing fails.
The default feature set of proc-macro1 tracks the most recent stable compiler
API. Functionality in proc_macro that is not yet stable is not exposed by
proc-macro1 by default.
To opt into the additional APIs available in the most recent nightly compiler,
the procmacro2_semver_exempt config flag must be passed to rustc. We will
polyfill those nightly-only APIs back to Rust 1.71.0. As these are unstable APIs
that track the nightly compiler, minor versions of proc-macro1 may make breaking
changes to them at any time.
RUSTFLAGS='--cfg procmacro2_semver_exempt' cargo build
Note that this must not only be done for your crate, but for any crate that depends on your crate. This infectious nature is intentional, as it serves as a reminder that you are outside of the normal semver guarantees.
Semver exempt methods are marked as such in the proc-macro1 documentation.
FAQs
Unknown package
The cargo package proc-macro1 receives a total of 0 weekly downloads. As such, proc-macro1 popularity was classified as not popular.
We found that proc-macro1 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.