Rust's Problematic Reliance on GitHub
old.reddit.com
old.reddit.com
Seems like everything is working by design. It also feels a bit deceiving to hide the fact that the topic was basically asking how to evade sanctions, and expect everyone else to do the legwork for them.
"Cloudflare Walks a Tight Line with Its Decision to Remain in Russia ": https://news.ycombinator.com/item?id=31398875
Irrelevant. GitHub complies with sanctions, and thus users from sanctioned countries cannot expect business to remain as usual. Services like crates.io have more pressing matters to deal with than helping third-parties circumvent sanctions.
From a cursory look, Rust does not rely at all on GitHub. Neither does Rust's crates format, which already support multiple sources including from git repos and package registry sources.
https://doc.rust-lang.org/cargo/appendix/glossary.html#regis...
Apparently Rust's Cargo package manager specifies crates.io as its default package registry source, but from the looks of it nothing stops anyone from providing their own package registry.
Rust is sort of less awesome without cargo. Its a valid point, but also github is sufficiently ubiquitous and rust community is busy building, 99.9% of the projects would use github anyway.
It isn't. Even though crates.io is the default package registry, Crates support both third-party package repositories and even git repos.
As explained in another post, the issue is actually a developer from Russia complaining that Russia was subjected to sanctions.
FTFY
Is there reason to believe that if crates.io were self-hosted, it wouldn't be subject to the same laws? Or is the theory that Microsoft/GitHub is covered by sanctions rules that a not-for-profit might not be?
If the packages are hosted by a company with a Brazilian branch or subsidiary, then I suppose that subsidiary carries the consequences
You can never lose your work as long as you retain a copy of the repo. You can never lose other people's work as long as you retain a copy of their repo. `cargo` does not require crates.io, can use other registries when they come into being, and can refer to modules by file path or by `http` uri.
However, he is trying the tact of talking about how crates.io uses GH's oauth; this is a clever thing to do since it ties explicit ownership of the repo to the user. There is nothing stopping crates.io to also use other ouaths the same way, as all of the major GH alternatives also support oauth and can be used for this purpose.
Crates.io most likely doesn't want to handle internal auth, as this becomes a maintenace nightmare for a 3? person team. Since the team is also small, adding other oauth->proof of repo onwership backends is presumably on their todo list but something they can't commit to.
Good news, though: https://github.com/rust-lang/crates.io (and they accept PRs)