3 ms·
You could argue that there are some crates in the Rust ecosystem that suffer from a deep dependency tree, I don't think you can argue that Rust developers are t
by 12baad4db82 4y ago
You could argue that there are some crates in the Rust ecosystem that suffer from a deep dependency tree, I don't think you can argue that Rust developers are trying to do this for the kernel.
The article states:
> The Rust-for-Linux developers understand this situation and are not envisioning adding the ability to pull in modules with a tool like Cargo
- nullc 4y ago> You could argue that there are some crates in the Rust ecosystem that suffer from a deep dependency tree Some? Dependency graphs of well over a hundred packages are ubiquitous. I've long since stopped being surprised when I compile a rust package that makes no network connections and see it (indirectly) pulling in multiple HTTPS libraries.
- Grimburger 4y ago> well over a hundred packages Tad understated. Popular rust http frameworks with basic functionality are hitting 300+ deps straight off the bat easily. For the security conscious, move to vendoring or alias cargo to always run in offline mode.
- 12baad4db82 4y agoRight, great example. I think 'understand the situation' refers to this. I imagine the Rust for Linux developers would be going through any dependencies they pull in with a fine comb, in this case a dependency that pulls in HTTPS libraries for presumably no reason should be rejected. If that particular dependency makes it into the kernel, well, then you can start complaining about it. But right now feels a bit premature.