5 ms·
Making dependency management easy, you end up with large tree of dependencies. It is one of the main concern I have with modern package manager. In my opinion,
by conaclos 4y ago
Making dependency management easy, you end up with large tree of dependencies.
It is one of the main concern I have with modern package manager.
In my opinion, it lacks a kind of trust management. Packages from a same team/author could belong to a same trust group. When a package get updated, we have to audit dependencies from new trust groups. This could create a culture of reduced and audited third-party dependencies.
- Yoric 4y agoI have been thinking for years of a different trust mechanism for packages, one that is closer to capabilities, i.e. what Android is doing these days for applications. Both approaches could certainly coexist!
- conaclos 4y agoCapabilities are great also! In particular at runtime.
- mid-kid 4y agoThis is unfortunately the reality, and the primary reason why I prefer ecosystems with a higher barrier of entry to publish your library or program on, like linux distributions. Libraries simply don't get on there unless there's a program using it, in demand by the users of the distribution. Similarly, it makes it less attractive for application developers to rely on a library that's not already in the repository, as this increases packaging and install friction.
- Yoric 4y agoI have just informally pitched both your idea and mine to the Rust security team :) We'll see what they think about it! If it somehow works, feel free to use this message as the proof that I got the idea from you :)
- conaclos 4y agoNice! Is there any place where the discussion is going?
- JadedBlueEyes 4y agoThere is a similar idea being explored with https://github.com/crev-dev/cargo-crev https://github.com/crev-dev/cargo-crev - you trust a reviewer who reviews crates for trustworthiness, as well as other reviewers.
- Yoric 4y agoThanks for the reference! Definitely worth looking into.