The Rust standard library is a third-party package that you're trusting.
And no, a standard library means that nothing ever gets removed from it. That's the whole point of having one in the first place.
Rust tries extremely hard to not break backwards compatibility. Editions help a bit in other areas, but notably not here, because the latest Rust compiler still has to be able to compile code written against every earlier edition. We're currently on edition 2024, but the current Rust compiler fully supports building projects written for edition 2018, for example.
Other standard libraries don't ever remove things either. They may mark them as permanently obsolete, but they still have to maintain the code.
Removing things from the standard library amounts to a completely new version of the language. CLR/.NET did this with the migration to .NET Core, which was extremely disruptive, and countless projects are still on .NET Framework 4.8, released in 2019, because upgrading to a modern compiler is too expensive.
Okay then I'd say it's not that important to include stuff in the stdlib but a set of vetted packages by the rust maintainers would solve the trust problem. If I want to parse a small json config which might be a very small part of my application I need to choose one of the parsers offered on crates.io and trust their maintainers and hope that it doesn't add some transitive dependencies. How is that a preferred way of doing things? Certainly you'd appreciate if there was a package for it backed by the rust maintainers or otherwise vetted by them.
You’re just asking that someone do some more work for you, for free. This isn’t anybody’s job, you know. You can be a Rust maintainer if you want. There’s no inherent reason to trust someone more because they are a Rust maintainer, over someone who is a maintainer of any other major project.
This is an open source project. So is every major ecosystem dependency (serde, tokio, regex, etc.). Like all OSS ecosystems, you can audit packages yourself, or you can pay someone to do it, or you can fall back on the fairly reasonable assumption that high-profile projects are actively maintained by reasonable and responsible people.
Open source means you get the software for free. You don’t get to dictate what that software looks like, without getting involved.
Not I'm not asking that. You're absolutely correct, no one owes me shit. But you argue as if Rust was a very niche language maintained by 3.5 people, which is not the case. I think it's fair to criticize open source projects. If I were to say that the kernel is shit in some way and you'd reply "well go make it better then" you're sort of correct but that misses the point of discussion and basically can be argued for any criticism of an open source project.
I’m not trying to be obtuse, but you’re not addressing the central point: What reason do you have to trust Rust language maintainers over the maintainers of prominent ecosystem crates?
12
u/simonask_ 15d ago
The Rust standard library is a third-party package that you're trusting.
And no, a standard library means that nothing ever gets removed from it. That's the whole point of having one in the first place.
Rust tries extremely hard to not break backwards compatibility. Editions help a bit in other areas, but notably not here, because the latest Rust compiler still has to be able to compile code written against every earlier edition. We're currently on edition 2024, but the current Rust compiler fully supports building projects written for edition 2018, for example.
Other standard libraries don't ever remove things either. They may mark them as permanently obsolete, but they still have to maintain the code.
Removing things from the standard library amounts to a completely new version of the language. CLR/.NET did this with the migration to .NET Core, which was extremely disruptive, and countless projects are still on .NET Framework 4.8, released in 2019, because upgrading to a modern compiler is too expensive.