#RUSTSEC-2025-0007 ring unmaintained
15 messages · Page 1 of 1 (latest)
Immediately, anyone can use features to change the backend they use.
sure
but that doesn't make the cargo-audit/cargo-deny stuff go away, I think?
which historically most people will want
I don't think it will
It's unfortunate they mix unmaintained with vulnerabilities, but I can't change that
I did eventually assume we'd change the default backend in reqwest
I was mostly concerned with whether a patch version upgrade would mean environments could no longer compile because of a missing build dep
sure
I recall a conversation at rust conf that that was getting better
And well, now it seems like a shrug
we're hoping we can get the advisory retracted by providing security-only maintenance for ring
Gotta deal with it
anyway, happy to review/advise on any changes in this area 👍