5 ms·
What's the security posture of actix-web these days? The impression I got from the temporary deletion of the repo and maintainer switch about six months ago[1]
by JackC 6y ago
What's the security posture of actix-web these days? The impression I got from the temporary deletion of the repo and maintainer switch about six months ago[1] was that actix-web was sort of a research platform rather than a production-ready server. It prioritized performance and ease of development in order to try (successful!) ideas the author had for writing really fast servers, and therefore made uses of unsafe code that many Rust developers thought unsuitable for production.
I don't mean to start drama -- I just feel like if the project is still prioritizing speed and experimentation over safety, that's worth including in comparisons like this, and if it's not anymore (or if I misunderstood the story in the first place), that would be good to know too.
[1] https://steveklabnik.com/writing/a-sad-day-for-rust https://steveklabnik.com/writing/a-sad-day-for-rust
- steveklabnik 6y agoI think you misunderstood the story in the first place; it was always intended to be production ready. The new team has, in my understanding, fixed the unsafe issues, and development continues.
- twic 6y agoIt's a bit more subtle than that, in that it depends on what you consider production-ready. It was originally intended to reach a level of robustness and soundness that the author considered production-ready, but which I personally didn't.
- steveklabnik 6y agoYeah. You could also argue that it was production ready because it was (and is) being used, in production, by a lot of folks.