Concerns Regarding the Choice of Rust for the Xfce Wayland Compositor
Brian Tarricone
brian at tarricone.org
Wed Jun 17 23:19:54 CEST 2026
On Wed, Jun 17, 2026, at 14:03, Mailing Lists wrote:
> I agree with your request for a security audit of Smithay and its dependencies, hopefully resulting in either a full dependency lock or in-tree/vendored crates. Hope to see something on that soon! :)
I think something like this deserves a big huge caveat and note: _none_ of Xfce's dependencies (Rust, C, anything) have gone through security audits, none are vendored, and we do not require a security audit before updating dependency versions.
Let's not try to use this as FUD against Rust dependencies. The same issue applies to our C dependencies, and I never hear anyone complaining about their lack of security audits or vendoring.
> You may also wish to use tools like `cargo-deny` to automatically scan dependencies for RustSec advisories, licensing problems, etc.
xfwl4 already uses cargo-deny for those purposes, and the CI build requires that the licensing and advisory checks pass.
Regards,
Brian
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mail.xfce.org/pipermail/xfce4-dev/attachments/20260617/e8675c16/attachment.htm>
More information about the Xfce4-dev
mailing list