So, don't add dependencies before you audit the code? That seems like a pretty reasonable ask to me.

You audit the code, then you run cargo update and you are pwned. Asking the user to not make mistakes is the c++ approach to security - it doesn’t work.