'bs58' jumped out at me as a random looking package name.
It implements the base58 encoding, which is used primarily by... Bitcoin.
I'd love to see the explanation of why "a TUI file manager" needs a crate closely associated with crypto coins and not much else.
It is precisely this kind of thing that makes Rust a no-go for most enterprises.
"I just want a CLI tool."
"Congratulations, your servers are mining crypto!"
PS: bs58 is maintained by one anonymous person and their package is used in just about every Rust crypto library and hence application. Compromise his account in the same manner as the 'xz tools' attack and you could still billions in crypto!
It doesn't actually use it, this is just referencing it in the dependency graph (Cargo.lock). bs58 is an optional (feature-gated) transitive dependency of another crate, which is never referenced at all in the top-level crate. The build.rs doesn't run or anything.
I believe there's (several) open issues about changing this behavior of the lock file, but I have moved on from Rust so don't know the status of things.
That said, this is confusing behavior. I remember I first noticed it when a bunch of crates were showing up in my lock file for every OS under the sun, even though I was specifically using a "wayland" (linux-only) feature.
Not to defend Rust's crazy culture of dependencies, mind you.
The lockfile confusion/bug is indeed a thing, but OP is noting that b58 was downloaded, which makes me think it's actually used.
I ran in to the lockfile bug myself a day ago and noticed that dependency-feature-flagged-crates show up in Cargo.lock, but their crates aren't downloaded.
I don’t know anything about this particular tool. But I’ll note that comparing package counts often doesn’t make sense between ecosystems, since some ecosystems (like Rust) lean heavily towards workspace patterns where several “physical” packages make up one “logical” unit.
(Rust even enforces for proc macros, which is why so many of the crates in your example end with “derive” or “macros.”)
I use nnn[0], a C tui file manager, and from the makefiles, you mostly need
readline
pcre
ncurses
pthread
and POSIX (and some unix thingies)
Which is why I love C projects, even with all the footguns. You have libraries with nice API that lets you write software without being on a treadmill to update the code every few months.
In my opinion, library authors should really minimize the amount of dependencies they have. Back to TypeScript, we are also the authors of https://github.com/okcontract/cells and we made a point of almost not having dependencies or even devDependencies.