3 ms·
Comparing Cargo package management to NPM is just silly. You can pull all the crates from crates.io and scan them for memory unsafety with Cargo and Rudra. I do
by natded 5y ago
Comparing Cargo package management to NPM is just silly. You can pull all the crates from crates.io and scan them for memory unsafety with Cargo and Rudra. I don't think anything similar is possible to do with C++ for example, let alone JS.
The alternative would be to arbitrarily slow down library development by including them in STD which is silly for many reasons (ie. it would hurt ecosystem, it would hurt the actual library development, it would hurt the STD development).
- pas 5y agonpm automatically does a "security audit" when you install packages. it's not a panacea, but a pretty big help.