Skip to content

*ring* is maintained again#2230

Merged
alex merged 1 commit into
rustsec:mainfrom
djc:retract-unmaintained-ring
Feb 22, 2025
Merged

*ring* is maintained again#2230
alex merged 1 commit into
rustsec:mainfrom
djc:retract-unmaintained-ring

Conversation

@djc

@djc djc commented Feb 22, 2025

Copy link
Copy Markdown
Member

Remove unmaintained advisory RUSTSEC-2025-0007.

@ctz and the rustls maintainers now have access to the crates.io entry for ring.

@alex

alex commented Feb 22, 2025

Copy link
Copy Markdown
Member

I think the correct way to do this is to add withdrawn = "2025-02-22"?

@djc

djc commented Feb 22, 2025

Copy link
Copy Markdown
Member Author

I think the correct way to do this is to add withdrawn = "2025-02-22"?

Ahh, I was looking for something like that.

@djc djc force-pushed the retract-unmaintained-ring branch from 8ef4f2d to 2da2d90 Compare February 22, 2025 16:33
@djc

djc commented Feb 22, 2025

Copy link
Copy Markdown
Member Author

I think the correct way to do this is to add withdrawn = "2025-02-22"?

Fixed.

@Shnatsel

Copy link
Copy Markdown
Member

Thank you!

It would be nice to add a line or two about rustls maintainers getting access into the advisory text to make the situation more clear.

@djc djc force-pushed the retract-unmaintained-ring branch from 2da2d90 to ed51835 Compare February 22, 2025 16:38
any reported security vulnerabilities may go unaddressed for prolonged periods
of time.

# Update: security maintenance only

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@ctz thoughts on this wording?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants