3 ms·
> do I even need this crate at all? 35 lines later I had the parts of dotenv I needed. I'm not saying you copy-pasted those 35 lines from dotenvy, but for the
by philsnow 1y ago
> do I even need this crate at all? 35 lines later I had the parts of dotenv I needed.
I'm not saying you copy-pasted those 35 lines from dotenvy, but for the sake of argument let's say you did: now you can't automatically benefit from dotenvy patching some security issue in those lines.
- a2128 1y agoTo benefit you have to actually trust the current and future maintainers of the package, its dependencies, the dependencies of its dependencies, etc. You can also automatically get breached in a supply chain attack, so it's a tradeoff
- skydhash 1y agoIf you REALLY need such update, you can easily subscribe to updates from the mainstream project (in whatever way it allows) and patch your version when that rare situation occurs.
- bsrkf 1y agoCan't benefit from them patching a security issue, but don't suffer from - them breaking something - a supply chain attack - them making a change which breaks your program - you having accidentally relied on a bug or an unintended behavior of their code (which they may fix at any moment) - many unneeded LOC in your codebase - absolution of ownership - relying on a dependency versus having written it yourself - in the latter case you'll automatically take responsibility - think much more about code's security/quality - have the knowledge to fix it and know exactly where to (in your 35-lines of code you yourself wrote) - more burdensome upgrades of your software - longer compilation speeds - having to monitor their program - is it abandoned, ownership transferred to dubious party - did the maintainer have a late night drunken stupor accepting bad pull requests - did they react to a CVE or not - did they change the license - do they have a license but added their own problematic paragraph - does the program "develop badly" (change its target scope in any problematic way) (take on more and more bloat, more unneeded functionality) - having worse of an overview of your total dependencies (since they may themselves rely on further crates you don't expect) - ... what's the trade-off now?
- infamouscow 1y agoYou forgot to add: legal council asking why you used a random package that triggered a contractually obligated security audit for your biggest client.
- arp242 1y agoWhat security issue? It's just read file by line, split by =, and return or call setenv. This is not OpenSSL we're talking about.