5 ms·
I automatically don't want to use this database because the number of third party dependencies are an unfixable, never-ending source of security vulnerabilities
by henning 2y ago
I automatically don't want to use this database because the number of third party dependencies are an unfixable, never-ending source of security vulnerabilities.
- bityard 2y agoSometimes I'm pretty sure people upvote stories just to see what happens in the comments.
- Idiot211 2y agoGuilty as charged. To steal a phrase from Reddit, "the true LPT is in the comments" The true insightful discussion comes in the comments.
- callamdelaney 2y agoLPT?
- orion138 2y agoI believe it means Life Pro Tip.
- airstrike 2y agoGuilty as charged.
- arccy 2y agoyeah, rust copied the dumpster fire that was npm, i shudder to think of the future of supply chain security when people say rewrite it in rust.
- norman784 2y agoWhat would a better model to manage dependencies in your opinion? I do like that is easy to add dependencies, but also don't like that a simple hello world Axum app IIRC is around 150 dependencies.
- reaperducer 2y agoYou don't have to have a solution to recognize that there is a problem.
- kibwen 2y agoThis is both right and wrong in a pernicious way. When pointing out a problem, you don't necessarily need to provide a better solution. However, if you refrain from providing a better solution, you are still implicitly asserting that there exists some better solution. So then it's possible to counter that with: a better solution may not exist. If you think a better solution does exist, then the burden of proof is on you to point out an existing solution that does better, or to otherwise establish that some better solution must exist. Rust could very well be at a global optimum for the problems it's trying to solve. Sometimes tradeoffs are just inevitable.
- arccy 2y agoit may be that rust tried to solve for the wrong problems, so while it may be at the global optimum, the foundation is just broken. that said, design choices like a flat package namespace are inexcusable. even npm started to move away from it.
- jpc0 2y agoI would say, evaluate how much work it would take to build it yourself, and if that is larger than your scope allows ask yourself some serious questions about whether the solution you came up with is overly complex. Some problems are hard to solve. But not all of them are. An example, and this is an observation. Where can I grab a library that just parses parses HTTP 1.0, HTTP 1.1 and HTTP 2.0 messages. Not a HTTP framework, something along the lines of httpparse. I pass it a buffer of bytes and out the other end pops a Result<error, HTTPResponse>. Sure there are hard problems to solve there but they are API design problems. I don't need tokio or some sort of web abstraction. If I want to use HTTP as a transport over carrier pidgeon I want to be able to do that with said library. Doesn't exactly exist though and because everyone just pulls in Tokio( I do mean the entire Tower stack or whatever it's called these says) nobody even notices the issue. And every single HTTP server rewrites that functionality with slightly different edge cases and bugs. That's basic internet infrastructure right there and we can't get a conical library for that yet you are arguing that 3 different implementations of the aame hash function pulled into the same project is viable?
- marcosdumay 2y agoI'm pretty sure everybody just copied from Perl. Go did something nice, and it would be good if more people copied. But it was also fairly recent.
- cb321 2y agoAlmost - CTAN (T for "TeX") predated CPAN by about 1 year (but may not have ever had as much automated fetching involved).
- wslh 2y agoNowadays this applies to everything that depends on modules that depend on more modules (e.g. NodeJS).
- rectang 2y agoYes, the amount of effort it takes to audit dependencies scales roughly linearly, so unless you're going to blindly install them, choosing to use a project with so many dependencies means taking on a tremendous amount of ongoing work.
- estebank 2y ago> the amount of effort it takes to audit dependencies scales roughly linearly With the lines of code, not the number of dependencies. 10 dependencies of 100 lines of code are arguably easier, but certainly not harder than a single dependency of 1000 lines of code.
- rectang 2y agoI should clarify that I mean auditing dependency-publisher authentication, rather than full code review. This returns us to status quo ante, back before supply chain attacks were something we worried about. Bugs and such from dependencies are an annoyance but a manageable problem. Supply chain attacks after publisher account compromise are catastrophic and are not manageable.
- estebank 2y agoI see, I have a different mental model for what auditing a dependency means. Auditing is "review the code and release processes of my dependency". In my mind what you describe would be "validating my Software Bill of Materials". It doesn't mean that either of us is wrong on what we call auditing, it just explains why sometimes we end up talking past each other in these conversations.
- marcosdumay 2y ago> auditing dependency-publisher authentication What does this mean? It means you'll trust the random people pushing code to cargo if you can prove they indeed are the random people they claim to be?
- 2y ago