> If it is a single-user, single-machine "app", you could use a plain UTF-8 text file which can be read and written to by any relevant text editor. No app is the best app in this case. This does depend in what kind of information you intend to CRUD.
I would similarly say a Rails app that uses a filesystem DB for records, sessions, logging, etc despite never having touched Ruby more than 3 times in the last 2 decades.
Many of your listed points are puzzling though.
> No single language can do all of that successfully, unless you ditch GUI and client-server models
There's nothing in the requirements about a GUI or client/server model. A CRUD app by API is pretty common.
> - Without external dependencies you will either be reinventing the wheel or adding lots of layers
No need for reinventing or using additional "layers" (whatever that's supposed to mean).
> - All software can be compromised or hacked, more layers equal more attack surface
"not easily" can be interpreted many ways, but assuring that nothing is 100% secure is irrelevant.
The question is quite sophisticated, within modern technology choices. However, the ease of CRUD app generation has been streamlined by Ruby to a ridiculous degree. Ruby has been great for this kind of thing for a long time, despite it's problems as a language for larger applications. People who are recommending Java, using Spring or not, are either ignorant or in denial. Java is a horrific choice for development speed and reliability for what amounts to requirements for a small application. Additionally, big/popular frameworks like Laravel/Django etc are also going to slower to develop and more problematic than a simple Rails app. This is primarily because of the ecosystems that shun the concept of a filesystem as a DB because it breaks their sensibilities about "the right way to do things".