Re: Concerns Regarding the Choice of Rust for the Xfce Wayland Compositor
"Brian Tarricone" <[email protected]> Wed, 17 Jun 2026 14:19:54 -0700
| Newsgroups | gmane.comp.desktop.xfce.devel.version4 |
|---|---|
| Message-ID | <[email protected]> |
--===============3215124283091019208== Content-Type: multipart/alternative; boundary=81faa20606850d4658d69f8818ef029a4eb82690 --81faa20606850d4658d69f8818ef029a4eb82690 Content-Type: text/plain Content-Transfer-Encoding: 7bit On Wed, Jun 17, 2026, at 14:03, Mailing Lists wrote: > I agree with your request for a security audit of Smithay and its dependencies, hopefully resulting in either a full dependency lock or in-tree/vendored crates. Hope to see something on that soon! :) I think something like this deserves a big huge caveat and note: _none_ of Xfce's dependencies (Rust, C, anything) have gone through security audits, none are vendored, and we do not require a security audit before updating dependency versions. Let's not try to use this as FUD against Rust dependencies. The same issue applies to our C dependencies, and I never hear anyone complaining about their lack of security audits or vendoring. > You may also wish to use tools like `cargo-deny` to automatically scan dependencies for RustSec advisories, licensing problems, etc. xfwl4 already uses cargo-deny for those purposes, and the CI build requires that the licensing and advisory checks pass. Regards, Brian --81faa20606850d4658d69f8818ef029a4eb82690 Content-Type: text/html Content-Transfer-Encoding: quoted-printable <!DOCTYPE html><html><head><title></title></head><body><div>On Wed, Jun = 17, 2026, at 14:03, Mailing Lists wrote:</div><blockquote type=3D"cite" = id=3D"qt" style=3D""><div>I agree with your request for a security audit= of Smithay and its dependencies, hopefully resulting in either a full d= ependency lock or in-tree/vendored crates. Hope to see something on= that soon! :)</div></blockquote><div><br></div><div>I think something l= ike this deserves a big huge caveat and note: _none_ of Xfce's dependenc= ies (Rust, C, anything) have gone through security audits, none are vend= ored, and we do not require a security audit before updating dependency = versions.</div><div><br></div><div>Let's not try to use this as FUD agai= nst Rust dependencies. The same issue applies to our C dependencie= s, and I never hear anyone complaining about their lack of security audi= ts or vendoring.</div><div><br></div><blockquote type=3D"cite"><div>You = may also wish to use tools like `cargo-deny` to automatically scan depen= dencies for RustSec advisories, licensing problems, etc.<br></div></bloc= kquote><div><br></div><div>xfwl4 already uses cargo-deny for those purpo= ses, and the CI build requires that the licensing and advisory checks pa= ss.</div><div><br></div><div>Regards,</div><div>Brian<br></div></body></= html> --81faa20606850d4658d69f8818ef029a4eb82690-- --===============3215124283091019208== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Xfce4-dev mailing list [email protected] https://mail.xfce.org/mailman/listinfo/xfce4-dev --===============3215124283091019208==--