• MalReynolds@slrpnk.net
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    před 8 měsíci

    TIL rust has some sort of ratings for libraries/dependency code. Cool! Is that intrinsic in some way?

    Speaking as a C/C++/python (and others) coder if that’s relevant, that’s been looking at Rust for a while…

    • Ephera
      link
      fedilink
      arrow-up
      12
      ·
      před 8 měsíci

      I’m not sure, what they mean with those ratings, to be honest.

      This whole article is about the yaml-rust library having been marked as unmaintained in the RUSTSEC advisory database: https://rustsec.org/packages/yaml-rust.html

      RUSTSEC is not intrinsic to the language, but it’s maintained by the Rust Foundation and there’s some really solid tooling, which can tell you in the blink of an eye that one of your dependencies is insecure.

      Well, and then there’s some unofficial projects which curate libraries, like https://awesome-rust.com and https://lib.rs (the latter also serves as an alternative frontend for the official package registry https://crates.io ).

    • lysdexic@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      3
      ·
      edit-2
      před 8 měsíci

      TIL rust has some sort of ratings for libraries/dependency code.

      A random guy going through the trouble of putting together a site to subjectively rate other people’s work is hardly something that’s language-specific.

      I’d wager that adding a single tag/field to represent the programming language is all it takes to make the system universal.

      Also, that’s not even language-specific. It’s package-centric.

      I get it, joining bandwagons is fun. That’s not a substitute for thinking things through, though.

      By the way, npm even supports package auditing, warnings, and autopromoting packages and its dependencies. You don’t hear people constantly parroting switching projects to Node.js over this, though.