You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm filing this well aware that this is not a security issue in itself (the crate is probably still good to use for now), but also wanted to document that rmp is currently pulling paste into the dependency tree that RUSTSEC-2024-0436 has been filed against.
I don't know what the crate does/did, so not sure how easy this is to change.
Cheers!
The text was updated successfully, but these errors were encountered:
loqusion
added a commit
to loqusion/tower-sesh
that referenced
this issue
Mar 8, 2025
Also wanted to flag this, this counts as a vulnerability for the purposes of tools such as cargo-deny. In my case it's not high severity since I only use rmp-serde as a dev-dependency, but if someone uses a similarly aggressive security policy on their crate as I do and has it as an actual dependency then their build just became broken.
dtolney didn't really leave any helpful notes behind, just a terse "no longer maintained" note so I don't know how to migrate this, it probably heavily depends on how this crate used paste.
hello!
I'm filing this well aware that this is not a security issue in itself (the crate is probably still good to use for now), but also wanted to document that
rmp
is currently pullingpaste
into the dependency tree thatRUSTSEC-2024-0436
has been filed against.I don't know what the crate does/did, so not sure how easy this is to change.
Cheers!
The text was updated successfully, but these errors were encountered: