git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH RFC 0/3] Introduce Rust and announce that it will become mandatorty

From
Patrick Steinhardt <ps@pks.im>
Date
Sep 23, 2025, 05:05 UTC
Message-ID
<aNIqgghQwyWV7Tis@pks.im>
In-Reply-To
<878qi66tyg.fsf@gentoo.org>
On Mon, Sep 22, 2025 at 10:47:03PM +0100, Sam James wrote:
Show 16 quoted lines
> "brian m. carlson" <sandals@crustytoothpaste.net> writes:
> > I don't think this is going to happen as you anticipate it will.  My
> > original policy was to target Debian stable's release for a year after
> > the new Debian stable came out and that will make using many crates
> > nearly impossible.  We are going to have to be _extremely_ careful about
> > dependencies in general and the things we are likely to use are things
> > like bindgen and cbindgen, where typically an old version will work just
> > fine and which are already packaged in major distros.  We are not going
> > to be adding dependencies willy-nilly and running `cargo update` every
> > other day.
> 
> That brings me significant comfort and I'm glad to hear it. I hope
> others agree with your position on having significant restraint on the
> use of external crates.
> 
> git has always been quite good about dependencies pre-Rust.

I certainly echo brian's sentiment here. Rust dependencies are easy to use, but they are also one part that worries me quite significantly due to multiple reasons:

  - Pulling in many dependencies opens us up for supply chain attacks.
  - Every single dependency is a source for vulnerabilities in general.
    We're already good enough in creating these ourselves.
  - Dependencies may have hard requirements on the Rust version,
    requiring us to bump the minimum required toolchain version.
  - In general, I'm not a fan of having even dozens of dependencies. It
    causes bloat and externalizes a bunch of knowledge.

So I think we should and need to be very conservative about adding any new dependencies. There will be cases where it makes sense, but every new dependency should be well-reasoned.

After this patch series lands, one of the next steps will also be to add a policy for how we want to use Rust in the Git project. brian has already written such a policy (see e.g. [1]), and it already mentions that we'll need to be careful about adding dependencies. Might be worth it to flesh that part out a bit more, but that's something we can discuss at a later point.

Patrick
[1]: <6d065f550fe871cf010409f7bd2a63438cf52723.1756496539.git.gitgitgadget@gmail.com>
Previous: Sam JamesNext: Michael Orlitzky
Message 9 of 10 in “Re: [PATCH RFC 0/3] Introduce Rust and announce that it will become mandatorty”
  1. Sergey FedorovSep 19, 2025
  2. Ezekiel NewrenSep 19, 2025
  3. Collin FunkSep 19, 2025
  4. Florian MärklSep 20, 2025
  5. Michael OrlitzkySep 22, 2025
  6. Sam JamesSep 22, 2025
  7. brian m. carlsonSep 22, 2025
  8. Sam JamesSep 22, 2025
  9. Patrick SteinhardtSep 23, 2025
  10. Michael OrlitzkySep 22, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.