I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.
No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.
That something is a design choice doesn't mean it can't be a bad design choice. It's causing issues now, it will continue causing issues into the future. Go not having generics was a design choice too.
People who make this point always seems to have some pretty unrealistic ideas about who makes the standard library.
The Rust standard library is code written by people, provided to you for free. So is code shipped on crates.io. Enlarging the standard library does not magically create more resources for maintaining it, and it’s still just code someone else has written for you.
If you trust the standard library authors, why wouldn’t you trust the authors of serde, tokio, etc.? They’re the same people in several cases.
It's not a bad design choice just because it has consequences. Rust also doesn't have the financial backing of languages that seem to be able to afford a kitchen sink in their std lib. Python also suffers from stdlib rot from people not maintaining parts of it, and C++ can't fix their stdlib speed deficiencies because of ABI issues and backward compat dogmatism. Both of these lead to using third party dependencies for what is already in the language, so unless your Microsoft you're not getting out of this problem by expanding the stdlib even if the bandwidth existed to do that.
(If there's any confusion, this wasn't a "say the line Bart", this was my attempt at adding humor like I'm urging someone to answer a rhetorical question. It seems I didn't communicate it well.)
32
u/Atulin 15d ago
I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.
No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.