3 ms·
> If you care about security, you have to audit your dependencies very carefully The problem is Cargo is yet another iteration of the npm-ization (maven-izatio
by zer8k 3y ago
> If you care about security, you have to audit your dependencies very carefully
The problem is Cargo is yet another iteration of the npm-ization (maven-ization?) of code. It requires a BDFL or a team of such BDFLs to proactively police the repos in order to prevent trivial supply chain attacks. Your statement misses the point that not only do people NOT do this it's now trivial to avoid it with Cargo.
This is not the same security risk that is present if you use git submodules and build with a makefile. The key difference is ease of use. Cargo, like NPM and to some extent Maven, are so easy to use you've accidentally created a massive attack surface.
The result will likely be yet another incarnation of JFrog or the like. Code will be audited, built into dylibs, and then pinned via some enterprise supply chain manager. This is a big lift for companies who might otherwise switch to Rust for new projects quicker.
Cargo is my main gripe with Rust almost all the time. So many people say "you can just build manually with rustc!" but this is not true. It's not as simple. Again, it would also be one thing if Cargo was just the package manager but it's also the build management system, test framework, etc. It's the ecosystem. It not only introduces supply chain attacks. It also introduces other attacks directly from the owners such as vengeful removal of packages, changes in CoC that ban certain libraries, etc. I don't like it. Of all package managers, it makes me feel the worst.
- wredue 3y agoThe issue is that if your language doesn’t NPM-ize your packages, developer write you off as not modern enough. The simple fact is that this seems to be what most developers want, AND this is not limited to JavaScript developers.
- howinteresting 3y agoThe ease of use outweighs the security concerns for most reasonable people.