Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUSTSEC-2025-0007: *ring* is unmaintained #400

Open
github-actions bot opened this issue Feb 22, 2025 · 2 comments
Open

RUSTSEC-2025-0007: *ring* is unmaintained #400

github-actions bot opened this issue Feb 22, 2025 · 2 comments
Labels
A-dependencies Area: Related to updating dependencies A-security Area: Security related P-low Priority: low, not on current prio list

Comments

@github-actions
Copy link
Contributor

ring is unmaintained

Details
Status unmaintained
Package ring
Version 0.17.10
URL briansmith/ring#2414
Date 2025-02-20

The author has announced an indefinite hiatus in its development, noting that
any reported security vulnerabilities may go unaddressed for prolonged periods
of time.

See advisory page for additional details.

@duracell
Copy link

There is an update:

After this advisory was published, the author graciously agreed to give access to the rustls team. The rustls team is committed to providing security (only) maintenance for ring for the foreseeable future.

So I guess not a (security) problem anymore.

@aawsome
Copy link
Member

aawsome commented Mar 2, 2025

Thanks for this information @duracell

@simonsan simonsan added A-dependencies Area: Related to updating dependencies A-security Area: Security related P-low Priority: low, not on current prio list labels Mar 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-dependencies Area: Related to updating dependencies A-security Area: Security related P-low Priority: low, not on current prio list
Projects
None yet
Development

No branches or pull requests

3 participants