Professional software development needs to include a software Bill of Materials to help track and manage things like this. https://www.cisa.gov/sbom
this post was submitted on 11 Jan 2026
1 points (100.0% liked)
Rust
8208 readers
2 users here now
Welcome to the Rust community! This is a place to discuss about the Rust programming language.
Wormhole
Credits
- The icon is a modified version of the official rust logo (changing the colors to a gradient and black background)
founded 3 years ago
MODERATORS
It would be good to know how these figures compare to e.g. pypi, npm.
Yeah unfortunately these numbers don't really allow any conclusions to be drawn at all.
Also they're not really related to supply chain security which is more about deliberate subterfuge. I think the interesting stat there would be how many authors are being trusted typically for each crate.
I have the feeling that this wasn't even done properly (e.g. checking default versions only). Using downloads alone is also not a good filter.
I may give this some time tomorrow and provide my own numbers.