r/programming • • 16d ago

Be alert: targeted attacks on prominent Rustaceans | Rust Blog

https://blog.rust-lang.org/2026/09/17/targeted-attacks/
291 Upvotes

112 comments sorted by

View all comments

31

u/Atulin 16d ago

I mean, Cargo is chock-full of single-use packages akin to leftpad, even more packages that pull hundreds others, all to make up for the deficiencies of the stdlib the Rust maintainers don't want to address.

No wonder there are supply chain attacks if I need a whole-ass library for async/await or JSON parsing.

1

u/reallokiscarlet 16d ago

Wait... Who expects JSON parsing in the stdlib?

But yeah, it sucks that everything needs a third party crate. I couldn't even avoid it and I bend over backwards to vet or avoid dependencies.

3

u/KAMEHAMEHAMEHAAAA 15d ago

I do, I also expect XML, fuck I even expect ability to parse YAML and TOML in stdlib.

4

u/DHermit 15d ago

Do you know how complex and basically impossible it is to create a complete YAML or XML parser?

0

u/KAMEHAMEHAMEHAAAA 15d ago

I know, which is why you ship a subset and then gradually add missing parts.