4 ms·
For licenses there's cargo-deny https://github.com/EmbarkStudios/cargo-deny https://github.com/EmbarkStudios/cargo-deny On the security standpoint and a wide n
by Keyframe 5y ago
For licenses there's cargo-deny https://github.com/EmbarkStudios/cargo-deny https://github.com/EmbarkStudios/cargo-deny
On the security standpoint and a wide net of crates.. that's a problem, same as with npm/yarn/pip/whatever and I agree on that. That one bugs me as well. Difficult to audit.
- galangalalgol 5y agoCargo-deny is accurate, but it accepts no legal or financial risk if it was in some case wrong and you infected a codebase with gplv3, and thus corporate lawyers everywhere ignore it. Edit: this post keeps getting up and down voted. I suspects it has to do with the phrase infected by gplv3. I like the license fine, but being realistic many businesses treat it like radioactive waste, so that has to be a consideration