Concerns Regarding the Choice of Rust for the Xfce Wayland Compositor

Brian Tarricone brian at tarricone.org
Wed Jun 17 23:19:54 CEST 2026


On Wed, Jun 17, 2026, at 14:03, Mailing Lists wrote:
> I agree with your request for a security audit of Smithay and its dependencies, hopefully resulting in either a full dependency lock or in-tree/vendored crates. Hope to see something on that soon! :)

I think something like this deserves a big huge caveat and note: _none_ of Xfce's dependencies (Rust, C, anything) have gone through security audits, none are vendored, and we do not require a security audit before updating dependency versions.

Let's not try to use this as FUD against Rust dependencies.  The same issue applies to our C dependencies, and I never hear anyone complaining about their lack of security audits or vendoring.

> You may also wish to use tools like `cargo-deny` to automatically scan dependencies for RustSec advisories, licensing problems, etc.

xfwl4 already uses cargo-deny for those purposes, and the CI build requires that the licensing and advisory checks pass.

Regards,
Brian
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mail.xfce.org/pipermail/xfce4-dev/attachments/20260617/e8675c16/attachment.htm>


More information about the Xfce4-dev mailing list