I'm still kind of baffled that the rust people saw what js was doing with npm and saying "that's a great idea", let's do that!
Or maybe it's just a lot of previous js devs doing this.
https://kerkour.com/rust-supply-chain-security-standard-library
Rust has a HUGE supply chain security problem
"If only Rust had this feature, we would use it for all our greenfield projects!" Said nobody. Rust adoption is stagnating not because it's missing some weird feature pushed by programming language theory fanatics, but because of a lack of focus on solving the practical problems that developers are facing