Re: [PATCH RFC 0/3] Introduce Rust and announce that it will become mandatorty
- From
Patrick Steinhardt <ps@pks.im>
- Date
- Sep 23, 2025, 05:05 UTC
- Message-ID
- <aNIqgghQwyWV7Tis@pks.im>
- In-Reply-To
- <878qi66tyg.fsf@gentoo.org>
On Mon, Sep 22, 2025 at 10:47:03PM +0100, Sam James wrote:
Show 16 quoted lines
> "brian m. carlson" <sandals@crustytoothpaste.net> writes: > > I don't think this is going to happen as you anticipate it will. My > > original policy was to target Debian stable's release for a year after > > the new Debian stable came out and that will make using many crates > > nearly impossible. We are going to have to be _extremely_ careful about > > dependencies in general and the things we are likely to use are things > > like bindgen and cbindgen, where typically an old version will work just > > fine and which are already packaged in major distros. We are not going > > to be adding dependencies willy-nilly and running `cargo update` every > > other day. > > That brings me significant comfort and I'm glad to hear it. I hope > others agree with your position on having significant restraint on the > use of external crates. > > git has always been quite good about dependencies pre-Rust.
I certainly echo brian's sentiment here. Rust dependencies are easy to use, but they are also one part that worries me quite significantly due to multiple reasons:
- Pulling in many dependencies opens us up for supply chain attacks.
- Every single dependency is a source for vulnerabilities in general.
We're already good enough in creating these ourselves. - Dependencies may have hard requirements on the Rust version,
requiring us to bump the minimum required toolchain version. - In general, I'm not a fan of having even dozens of dependencies. It
causes bloat and externalizes a bunch of knowledge.So I think we should and need to be very conservative about adding any new dependencies. There will be cases where it makes sense, but every new dependency should be well-reasoned.
After this patch series lands, one of the next steps will also be to add a policy for how we want to use Rust in the Git project. brian has already written such a policy (see e.g. [1]), and it already mentions that we'll need to be careful about adding dependencies. Might be worth it to flesh that part out a bit more, but that's something we can discuss at a later point.
Patrick
[1]: <6d065f550fe871cf010409f7bd2a63438cf52723.1756496539.git.gitgitgadget@gmail.com>