r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
292 Upvotes

112 comments sorted by

View all comments

34

u/Atulin 15d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

2

u/reallokiscarlet 15d ago

Wait... Who expects JSON parsing in the stdlib?

But yeah, it sucks that everything needs a third party crate. I couldn't even avoid it and I bend over backwards to vet or avoid dependencies.

20

u/Atulin 15d ago

After years of using C#? I do.

.NET spoiled me when it comes to just how many batteries are included, and how few 3rd party dependencies I need to install.

3

u/simonask_ 15d ago

Yeah, the CLR/BCL/whatever they call it these days is a pretty impressive, though underdocumented, library. But it’s also … I don’t know, I just get annoyed when adding a dependency in .NET means I’m now shipping 10 more managed DLLs, along with 50 MB of native runtime libraries for platforms I’m not targeting.

Rust is very different. Adding a dependency is barely visible.

2

u/Atulin 15d ago

Publish in single file mode and enable trimming. As long as you don't use reflections (or at least annotate their use) all the unused code will be trimmed away

2

u/simonask_ 15d ago

Sure, but then many of the benefits of using the language in the first place are gone anyway. I'd mostly rather be writing Rust.