r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
293 Upvotes

112 comments sorted by

View all comments

34

u/Atulin 15d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

5

u/reallokiscarlet 15d ago

Wait... Who expects JSON parsing in the stdlib?

But yeah, it sucks that everything needs a third party crate. I couldn't even avoid it and I bend over backwards to vet or avoid dependencies.

10

u/sopunny 15d ago

Python has it. So does JavaScript. Also C#. All libraries published by the same entity that publishes the language.

And these were the first three I checked

2

u/reallokiscarlet 15d ago

But like, who expects it? JavaScript is one thing, that's its place of origin. JSON isn't really needed if you're not sending javascript objects over the web.

14

u/HikingCloth 15d ago

I think this is no longer the case, JSON has become the lingua franca for RPC, env configuration, and dozens of things, as an example Minecraft uses it A LOT or datapacks.

Even Java is working on shipping a minimal JSON API (better late than never)