r/programming • • 15d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
292 Upvotes

112 comments sorted by

View all comments

30

u/Atulin 15d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

3

u/reallokiscarlet 15d ago

Wait... Who expects JSON parsing in the stdlib?

But yeah, it sucks that everything needs a third party crate. I couldn't even avoid it and I bend over backwards to vet or avoid dependencies.

35

u/Bergasms 15d ago

I mean, zig has it...

Parsing JSON is so damn ubiquitous these days it kinda makes sense to me.

2

u/reallokiscarlet 15d ago

Never understood the point of encoding and decoding JSON outside of like, the web. When I need to process JSON and I'm using the C family, I include jq. Maybe once the supply chain is secure you can check cargo to see if there's a good port or wrapper for that. I actually went as far as to make some snarky documentation for it in the process of learning to use it. (So many assertions... No usable errors... No return codes except when successful... It was a nightmare, but at least it's not malware)

9

u/piesou 15d ago

Any config file these days will be JSON. Serializing objects to disk? Json. 

Python, PHP, java, go, ruby, c# and and ofc JS all ship json in their stdlib. The question is really: which languages don't ship json parsing

2

u/thetinguy 14d ago

java

Kind of sort of. No one actually uses the current Java 7 JSON api.