
A library cannot add new fundamental things to a language, or, possibly more importantly remove bad ideas from a language.
The article makes a point to say these features are for library writers to help them write simpler APIs for inexperienced users to use. But misses the point of different languages have different footguns that inexperienced users can trip up on.





You cannot do that analysis with one sample. Why pick one day? That is an arbatary amount? Pick the 1 hour or minute that the CVE was released and you will find rust might be responsible for 100% of CVEs, Take a Week or year and that number drops dramatically. Pick the next day and that drops to 0%. You can select any % you want if you change what time period you are looking at.
The fact that there has been one cve in 5 years of rust in the kernel is a bigger tell. There will be more rust CVEs, and each one is going to be big news as they happen so rarely.