Show HN: I made a zero dependency Bitcoin math implementation in C
github.com
github.com
#include <ctype.h>
#include <math.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <time.h>
They are all standard headers, required in a hosted implementation of ISO C. Only stripped down C implementations which the standard calls "freestanding" can omit parts of the standard library.Except for <stdint.h>, all existed in 1989 ANSI C; though not with all the content they have now.
If you write a C program, you have a dependency on a C implementation; it's not going to compile itself. That's an external dependency: something not in your program. It is a second party dependency. First party is you, second is the programming language and library (and perhaps the platforms you are targeting and what they supply). Third party external dependencies are anything not in your program or language implementation or platform. The things you have to tell the user to download and install, possibly from source.
One second-party dependency this code has is on a Windows-like command interpreter which provides a "cls" command, for the several system("cls") calls the code makes to clear the screen.
We can't infer a dependence of that kind from seeing standard header includes. That does not raise the suspicion above background levels.
Would you make the same argument for reference implementations of algorithms? For example, small details leading to bugs that can be compromised?
At some point people have to be responsible for themselves...
If you have a char array[] that can hold arbitrary binary data, some of the values can be negative, since char is usually signed. isapha(array[i]) is undefined behavior if array[i] is a negative value other than EOF. If it doesn't crash, it will likely index backwards into a lookup table and access garbage.
EDIT: I see from the dead reply that this is a bot, or a "vibe coder" who doesn't understand the code. The bizarre remark "<ctype h> is solely to allow me to define structs using typdef" is nonsensical. Whoever (or whatever) wrote the code understands that <ctype.h> provides functions like isalpha and is unrelated to defining C types.
EDIT: I think I can fix the isalnum bug risk that you identified by checking that the value of the ch variable in the get_string_input function is non-negative before allowing it to be appended to str.