Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUSTSEC-2019-0031: spin is no longer actively maintained #41

Open
github-actions bot opened this issue Dec 18, 2019 · 2 comments
Open

RUSTSEC-2019-0031: spin is no longer actively maintained #41

github-actions bot opened this issue Dec 18, 2019 · 2 comments
Assignees
Labels
enhancement New feature or request help wanted Extra attention is needed security About security concerns

Comments

@github-actions
Copy link

spin is no longer actively maintained

Details
Status unmaintained
Package spin
Version 0.5.2
URL mvdnes/spin-rs@7516c80
Date 2019-11-21
Unaffected versions > 0.5.2

The author of the spin crate does not have time or interest to maintain it.

Consider lock_api (a subproject of
parking_lot) as an alternative which also supports no_std environments.

See advisory page for additional details.

@imclint21 imclint21 added enhancement New feature or request help wanted Extra attention is needed security About security concerns labels Dec 18, 2019
@shuni64
Copy link
Contributor

shuni64 commented Dec 29, 2019

We'll have to wait until the ring authors fix it in briansmith/ring#921.
We'll also have to update our dependencies to use a newer version of ring, which is probably going to involve changing parts of Lucid to use async-await syntax, although we can't do that without using the git repository revision of warp directly because version 0.2 isn't released on crates.io yet.

But this isn't too important to fix immediately, the spin crate still works and shouldn't break in the foreseeable future. Once everything is up-to-date and ring doesn't use it anymore this issue can be closed without requiring additional attention.

@imclint21
Copy link
Member

Alright @CephalonRho!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request help wanted Extra attention is needed security About security concerns
Projects
None yet
Development

No branches or pull requests

3 participants