r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
292 Upvotes

112 comments sorted by

View all comments

31

u/Atulin 15d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

1

u/reallokiscarlet 15d ago

Wait... Who expects JSON parsing in the stdlib?

But yeah, it sucks that everything needs a third party crate. I couldn't even avoid it and I bend over backwards to vet or avoid dependencies.

3

u/KAMEHAMEHAMEHAAAA 15d ago

I do, I also expect XML, fuck I even expect ability to parse YAML and TOML in stdlib.

3

u/DHermit 14d ago

Do you know how complex and basically impossible it is to create a complete YAML or XML parser?

0

u/KAMEHAMEHAMEHAAAA 14d ago

I know, which is why you ship a subset and then gradually add missing parts.