4 ms·
This is the main reason we have banned Rust across my Org. Every third party library needs to be audited before being introduced as a vendored dependency which
by armitron 2y ago
This is the main reason we have banned Rust across my Org. Every third party library needs to be audited before being introduced as a vendored dependency which
is not easy to do with the bloated dependency chains that Cargo promotes.
- selfmodruntime 2y agoHow do you solve this for other languages you use?
- armitron 2y agoOur main languages are Go and OCaml. We can leverage third party libraries without easily running into transitive dependency hell as there’s an implicit understanding in these communities that large number of dependencies is not a good thing. Or, expressed differently, there is coarser granularity in what ends up being a library. This is not the case with Cargo which has decided to follow the NPM approach.
- lifthrasiir 2y agoAt least in my experience, Go packages and Rust crates are much coarser than NPM packages. (Look at actual direct and indirect dependencies in cargo-watch to judge it by yourself.) I think Go prefers and actually has resource to keep mostly centralized approaches, while Rust crates are heavily distributed and it takes longer for the majority to settle on a single solution.
- hu3 2y agoI've seen this approach go a long way with languages that have a large standard library. Go and C# .NET comes to mind.
- simonask 2y agoI'm sorry, but that feels like an incredibly poorly informed decision. One thing is to decide to vendor everything - that's your prerogative - but it's very likely that pulling everything in also pulls in tons of stuff that you aren't using, because recursively vendoring dependencies means you are also pulling in dev-dependencies, optional dependencies (including default-off features), and so on. For the things you do use, is it the number of crates that is the problem, or the amount of code? Because if the alternative is to develop it in-house, then... The alternative here is to include a lot of things in the standard library that doesn't belong there, because people seem to exclude standard libraries from their auditing, which is reasonable. Why is it not just as reasonable to exclude certain widespread ecosystem crates from auditing?
- cmrdporcupine 2y ago> One thing is to decide to vendor everything - that's your prerogative - but it's very likely that pulling everything in also pulls in tons of stuff that you aren't using, because recursively vendoring dependencies means you are also pulling in dev-dependencies, optional dependencies (including default-off features), and so on. What you're describing is a problem with how Cargo does vendoring, and yes, it's awful. It should not be called vendoring, it is just "local mirroring", which is not the same thing. But Rust can work just fine without Cargo or Crates.io.
- skywal_l 2y agoThe dependency hell issue is not directly related to Rust. The Rust language can be used without using any dependency. Have you banned javascript and python too?
- Zagitta 2y agoAnd in a similar vein have they audited the runtimes of all the languages they use? Because those a dependencies too and in many ways even more critical than libraries.
- OtomotO 2y agoGood on you, this approach will keep you employed for a looooooooong time, because someone has to write all that code then, right? ;)
- mu53 2y agoTBH, I have adjusted my programming recently to write more stuff myself instead of finding a library. Its not that bad. I think ChatGPT are really good at these at those types of questions since it can analyze multiple from github and give you an answer averaging them together. Also, if you just have a really well defined problem, its easy to just whip out 10-50 lines to solve the issue and be done with it
- joatmon-snoo 2y agoThis is what lockfiles are for.
- cmrdporcupine 2y agoWhy ban Rust instead of just banning Cargo? It's entirely possible to use Rust with other build systems, with vendored dependencies. Crates.io is a blight. But the language is fine.