@kkarhan I think you misunderstand. I am not asking support from Rygorous.

It is simply not possible for me to know the provenance of all image data that I may process. So then my only option is to somehow avoid the possibility of any code from Rygorous being on my system at all.

But when I write a program with Rust/Cargo, it commonly pulls in tens or hundreds of transitive dependencies which I see only by package name. Other modern package managers work similarly. In this case, it has been copy-and-pasted into the otherwise well-regarded Servo project.

I am simply asking that he name his libraries to accurately reflect their hazardous not-fit-for-use nature.