>dep hell
As a C programmer, i'm always a little panic how a small Rust Program can pull in that many crates when compiling.
As a C programmer, i'm always a little panic how a small Rust Program can pull in that many crates when compiling.
I've definitely cloned down my fair share of C projects, mashed the make command into my terminal, and watched the gcc/clang logs fly by and never batted an eye beyond checking the sha256sum on any downloaded tarballs.
There's a valid argument to be made about supply chain attacks, but there does exist tooling to lock that down, and I would argue that any serious software development firm should be auditing every third party dependency they take on.