From: Patrick Steinhardt Date: Tue, 23 Sep 2025 05:05:06 GMT Subject: Re: [PATCH RFC 0/3] Introduce Rust and announce that it will become mandatorty Message-ID: In-Reply-To: <878qi66tyg.fsf@gentoo.org> On Mon, Sep 22, 2025 at 10:47:03PM +0100, Sam James wrote: > "brian m. carlson" writes: > > I don't think this is going to happen as you anticipate it will. My > > original policy was to target Debian stable's release for a year after > > the new Debian stable came out and that will make using many crates > > nearly impossible. We are going to have to be _extremely_ careful about > > dependencies in general and the things we are likely to use are things > > like bindgen and cbindgen, where typically an old version will work just > > fine and which are already packaged in major distros. We are not going > > to be adding dependencies willy-nilly and running `cargo update` every > > other day. > > That brings me significant comfort and I'm glad to hear it. I hope > others agree with your position on having significant restraint on the > use of external crates. > > git has always been quite good about dependencies pre-Rust. I certainly echo brian's sentiment here. Rust dependencies are easy to use, but they are also one part that worries me quite significantly due to multiple reasons: - Pulling in many dependencies opens us up for supply chain attacks. - Every single dependency is a source for vulnerabilities in general. We're already good enough in creating these ourselves. - Dependencies may have hard requirements on the Rust version, requiring us to bump the minimum required toolchain version. - In general, I'm not a fan of having even dozens of dependencies. It causes bloat and externalizes a bunch of knowledge. So I think we should and need to be very conservative about adding any new dependencies. There will be cases where it makes sense, but every new dependency should be well-reasoned. After this patch series lands, one of the next steps will also be to add a policy for how we want to use Rust in the Git project. brian has already written such a policy (see e.g. [1]), and it already mentions that we'll need to be careful about adding dependencies. Might be worth it to flesh that part out a bit more, but that's something we can discuss at a later point. Patrick [1]: <6d065f550fe871cf010409f7bd2a63438cf52723.1756496539.git.gitgitgadget@gmail.com>