3 ms·
> Rust and Cargo make it challenging to develop a project in a fully "secure" fashion, C/C++ has a better story there. Complete absence of dependency managemen
by exDM69 4y ago
> Rust and Cargo make it challenging to develop a project in a fully "secure" fashion, C/C++ has a better story there.
Complete absence of dependency management and a myriad of incompatible build tools is a "better story"?
You can have this "story" in Rust by just disabling crates.io centralized registry. Which still leaves you in a better position than C++ because you can use the build tool and dependency management locally and do whatever you're used to doing in C++ land (put 3rd party code in your repo, install them via some other packaging tool etc). Or if you insist on going the whole way, you can invoke rustc via your favorite flavor of make.
On a more realistic note, if you're working with in a very safety/security conscious environment, and still depend on 3rd party code: you could set up your local package registry and have people vet the 3rd party dependencies. Yes, it costs time and money but at least you get the tools to do it from the language ecosystem.
I've been professionally involved with the C/C++ way of doing things for decades and I find the Rust build and dependency management tooling a huge improvement.
- pjmlp 4y agoDepends on the platform, VC++ plus NuGET and nowadays vcpkg, make it pretty sweet, same applies to lesser extent on Apple world. Maybe others should do more that just ship compiler + linker.