Cargo pulled in something like 105 dependencies to build it.
Although, as an apples to apples comparison, it does only have 2 use statements.
Cargo pulled in something like 105 dependencies to build it.
Although, as an apples to apples comparison, it does only have 2 use statements.
Here is a http health check in 19 lines using only the rust standard library.
There’s a happy medium to be had.
I’d also disagree this is not at all a language problem - I think it’s both, in that the language has moved an awful lot of core functionality into the crate ecosystem, where there are a bewildering array of options for almost any need. The resulting explosion in the dependency graph is an entirely foreseeable consequence — partially of that language design decision and partially due to the “npm culture” (for lack of a better description.)
The list goes on. While I'm not a Rust developer, there's probably hundreds of libraries because the problem is structured into a lot of small parts, and frameworks are expected to be able to satisfy the functionality you expect without needing to bypass it.
(The signal_hook crate even contains documentation on those pitfalls. https://docs.rs/signal-hook-registry/1.4.1/signal_hook_regis...)
I mean sure, reinvent the wheel. But it might do good to at least have an inkling what those 105 dependencies for your http listener did.
I ended up going with sigwaitinfo since the attempts you likely saw on matrix which is perfect for my application that will only ever run on modern linux kernels.
Combining that with the stdlib health check above and we end up with a dead simple health checking signal handling service pattern that works well and easy to confirm is free of supply chain attacks.
:)
https://en.m.wikipedia.org/wiki/No_true_Scotsman
Not sure if that's a good analogy, but put it out there, to see what people say.