logoalt Hacker News

vsgherziyesterday at 6:17 PM7 repliesview on HN

Supply chain incidents suck and we need to do better. Personally for rust I’m a proponent of the foundation supporting a few core crates that go under the same audit procedure as the main rust language and give funding to the project to limit supply chain vulns. I don’t think the right answer is to remove systems like crates or npm. Crate and npm are a boon for many developers.


Replies

vsgherziyesterday at 6:18 PM

Crates has also been making efforts to include rust sec, but in addition to the above I would like the community to shy away from many small dependencies to a few larger ones just as tokio has

show 2 replies
kibwenyesterday at 8:51 PM

A ton of the most popular crates on crates.io are already first-party crates provided by the Rust organization itself. This is often overlooked when people are wringing their hands about Rust crate graphs. Looking at the top 10 list of most-downloaded crates on the front page of crates.io, the only one not either from the Rust organization or from a Rust core maintainer is the base64 crate.

hacker_homieyesterday at 6:35 PM

Move high value crates into the standard library?

show 4 replies
suprfsatyesterday at 6:20 PM

do we really need both npm and nmp though

show 1 reply
dijityesterday at 7:20 PM

honestly I thought this was the end goal of blessed.rs

PunchyHamsteryesterday at 6:25 PM

nah, remove NPM, nothing good comes out of that.

2ndorderthoughtyesterday at 6:32 PM

[dead]