Re: Concerns Regarding the Choice of Rust for the Xfce Wayland Compositor

"Brian Tarricone" <[email protected]> Wed, 17 Jun 2026 14:19:54 -0700
Newsgroups gmane.comp.desktop.xfce.devel.version4
Message-ID <[email protected]>
--===============3215124283091019208==
Content-Type: multipart/alternative;
 boundary=81faa20606850d4658d69f8818ef029a4eb82690

--81faa20606850d4658d69f8818ef029a4eb82690
Content-Type: text/plain
Content-Transfer-Encoding: 7bit

On Wed, Jun 17, 2026, at 14:03, Mailing Lists wrote:
> I agree with your request for a security audit of Smithay and its dependencies, hopefully resulting in either a full dependency lock or in-tree/vendored crates. Hope to see something on that soon! :)

I think something like this deserves a big huge caveat and note: _none_ of Xfce's dependencies (Rust, C, anything) have gone through security audits, none are vendored, and we do not require a security audit before updating dependency versions.

Let's not try to use this as FUD against Rust dependencies.  The same issue applies to our C dependencies, and I never hear anyone complaining about their lack of security audits or vendoring.

> You may also wish to use tools like `cargo-deny` to automatically scan dependencies for RustSec advisories, licensing problems, etc.

xfwl4 already uses cargo-deny for those purposes, and the CI build requires that the licensing and advisory checks pass.

Regards,
Brian
--81faa20606850d4658d69f8818ef029a4eb82690
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html><html><head><title></title></head><body><div>On Wed, Jun =
17, 2026, at 14:03, Mailing Lists wrote:</div><blockquote type=3D"cite" =
id=3D"qt" style=3D""><div>I agree with your request for a security audit=
 of Smithay and its dependencies, hopefully resulting in either a full d=
ependency lock&nbsp;or in-tree/vendored crates. Hope to see something on=
 that soon! :)</div></blockquote><div><br></div><div>I think something l=
ike this deserves a big huge caveat and note: _none_ of Xfce's dependenc=
ies (Rust, C, anything) have gone through security audits, none are vend=
ored, and we do not require a security audit before updating dependency =
versions.</div><div><br></div><div>Let's not try to use this as FUD agai=
nst Rust dependencies.&nbsp; The same issue applies to our C dependencie=
s, and I never hear anyone complaining about their lack of security audi=
ts or vendoring.</div><div><br></div><blockquote type=3D"cite"><div>You =
may also wish to use tools like `cargo-deny` to automatically scan depen=
dencies for RustSec advisories, licensing problems, etc.<br></div></bloc=
kquote><div><br></div><div>xfwl4 already uses cargo-deny for those purpo=
ses, and the CI build requires that the licensing and advisory checks pa=
ss.</div><div><br></div><div>Regards,</div><div>Brian<br></div></body></=
html>
--81faa20606850d4658d69f8818ef029a4eb82690--

--===============3215124283091019208==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Xfce4-dev mailing list
[email protected]
https://mail.xfce.org/mailman/listinfo/xfce4-dev

--===============3215124283091019208==--