That’s more than can be said about hand rolled equivalents in C/C++.
That’s more than can be said about hand rolled equivalents in C/C++.
* https://chromium.googlesource.com/chromiumos/third_party/rus...
* https://searchfox.org/mozilla-central/source/supply-chain/au...
It's quite likely that most of your dependencies were already audited.
(You can check the files I linked and see audits between deltas for minor version updates)
I've heard the alarms about dependencies and I'm not sold. I feel like this is bleeding over from the JS/frontend world where people don't choose to do the above, for whatever reason.
Whenever I add a dependency in Rust I look at crates.io downloads, dependents (any big projects there?), github stars, I browse the issues to see what sort of problems have been reported and when, with what sort of replies from the author, how many contributors there are, release history, what commits look like, and what other stuff the authors have worked on. I use a lot of dependencies, and I do rewrite stuff myself when I feel like I can't rely on a dependency.
The big difference with a distro is that I choose to trust the distro maintainers, which is only a handful of people. Whereas with your hierarchical trust, you choose to trust many random people.