Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On the other hand it means you don't automatically get security fixes and have to manually set up CVE monitoring and rebuild your application every time a CVE appears.

Of course if it appears in an old version the author won't bother to backport the fix so you will have to bump the dependency to the latest, doing all the API changes that you didn't want to do.



Are we still talking about Rust or have we moved on to general grumbling about life?


Any language with an insufficient standard library and a need to import small modules in large numbers.

rust is one of them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: