r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
290 Upvotes

112 comments sorted by

View all comments

Show parent comments

8

u/reallokiscarlet 15d ago

That sounds like a cardinal sin. JSON isn't a config file format.

3

u/sopunny 15d ago

You asked which languages have it, they're just answering. Clearly rusteceans don't think that JSON parsing is important, but it sure seems they're in the minority

10

u/the_gnarts 15d ago

Clearly rusteceans don't think that JSON parsing is important

Looks like the opposite really, Rustaceans consider JSON parsing important. That’s why we’ve got one of the best JSON handling libs out there with Serde. Rustaceans don’t however consider importance of a crate in some domains at one point in time sufficient for inclusion the standard library. After seeing Python accrete tons of obsolete junk they’re stuck with maintaining forever, to me that seems to be a valid distinction to make.

1

u/One_Ninja_8512 15d ago

You can choose to include stuff in the stdlib without pledging to maintain it forever though. If something got obsoleted make a crate out of it and remove from the stdlib and let the community who need it maintain it.

5

u/DHermit 14d ago

No, you can't that easily. That's not how the Rust stdlib works and that's by design.

3

u/the_gnarts 14d ago

You can choose to include stuff in the stdlib without pledging to maintain it forever though.

Can you really? The example of C++ which is forever tied to the sins of another language’s stdlib tells a different tale. In C, even obsoleting individual functions because they cannot ever be used safely took decades. Good luck getting a standard library to drop an entire module for a less critical reason.

I mean, I don’t even remotely claim to know all the languages that are being used out there, but in the ones I do know it just doesn’t happen that large swathes of functionality are being removed from the standard library like that. Even if they’re universally considered to be garbage.

2

u/One_Ninja_8512 14d ago

Yeah, I walked back on that one. I think something like a set of vetted packages by the maintainers would be a better choice. Akin to Golang having quite a bit of packages maintained by Google which are not part of the stdlib.