And it would have been 0 crates in .NET or Go. Even after adding a web server.
And it would have been 0 crates in .NET or Go. Even after adding a web server.
Four. Though you initially asked for five features, so let me add lexopt, which brings the number up to 29.
> That's why projects end up with 100s of crates, sometimes 1000s.
If your argument is "out of 1000s of dependencies 29 could be easily removed" then it does sound a lot less of a deceive change when it comes to supply chain security.
And even getting those 29 right is hard. For example people do want regular expressions with lookaround assertions, but most implementations suffer from runtime blowups (resulting in ReDoS attacks) and improving on that is a fairly recent research[0], so this is hardly a trivial and settled thing to implement. So often there's a tradeoff between choosing more powerful regular expressions and DoS-resistant ones, not one standard.