Despite personal opinions on Rust use-cases/scope-creep (why not use a higher level llvm language if you want safer syntax.) Cargo like npm, php pear, and pip3 etc. traded convenience for long-term security rot, high maintenance cycles, and version instability within downstream source code.
i.e. the proponents will likely feel like they are in perpetual Beta, as dependent resources permute under conflicting use-cases.
People often confuse convenience with Workmanship Standards, and rotten code trees in any language have the same result. This is not a new phenomena ( https://en.wikipedia.org/wiki/Second-system_effect ) =3
This attitude seems to be wide-spread in Python land, unfortunately. Even prominent packages don't properly lock their versions and hashes. Many people deliver, I dare say, shoddy work.