How Rust dependency management actually works, and why its security properties differ from every other ecosystem in a polyglot estate. Covers the crates.io registry and its ownership and yanking model, Cargo.lock and why an application commits it while a library typically does not, the build script as the single most consequential execution surface in this ecosystem, feature unification and the code paths it can silently enable, semantic versioning enforcement that is stronger here than in most package managers, the audit and advisory tooling built specifically for Rust, and vendoring against registry dependencies for an air gapped build. Closes with overriding a vulnerable transitive crate, upgrading a dependency several major versions behind, and the Rust appendix of a policy that has to hold across many ecosystems. Companion to the published Java, JavaScript, Python and Go courses in the same series.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.