<!DOCTYPE html><html><head><title></title></head><body><div>On Wed, Jun 17, 2026, at 14:03, Mailing Lists wrote:</div><blockquote type="cite" id="qt" style=""><div>I agree with your request for a security audit of Smithay and its dependencies, hopefully resulting in either a full dependency lock or in-tree/vendored crates. Hope to see something on that soon! :)</div></blockquote><div><br></div><div>I think something like this deserves a big huge caveat and note: _none_ of Xfce's dependencies (Rust, C, anything) have gone through security audits, none are vendored, and we do not require a security audit before updating dependency versions.</div><div><br></div><div>Let's not try to use this as FUD against Rust dependencies.  The same issue applies to our C dependencies, and I never hear anyone complaining about their lack of security audits or vendoring.</div><div><br></div><blockquote type="cite"><div>You may also wish to use tools like `cargo-deny` to automatically scan dependencies for RustSec advisories, licensing problems, etc.<br></div></blockquote><div><br></div><div>xfwl4 already uses cargo-deny for those purposes, and the CI build requires that the licensing and advisory checks pass.</div><div><br></div><div>Regards,</div><div>Brian<br></div></body></html>