2 ms·
It's not constant, most C projects don't have anywhere near the number of library dependencies seen in your typical cargo project. From a supply chain attack pe
by armitron 3y ago
It's not constant, most C projects don't have anywhere near the number of library dependencies seen in your typical cargo project. From a supply chain attack perspective, Rust and Node promote ecosystems that are total disasters.
- lifthrasiir 3y agoMost software projects are not written in C. Conversely C would be used for projects where C would be less annoying than alternatives, and that condition largely precludes projects with many required dependencies. And every language-level package manager, not just that of Rust and Node, would be a disaster from the supply chain attack perspective---it can even be said that C is suffering from the huge amount of supply chain attacks in spite of the lack of good language-level package manager.