-
Notifications
You must be signed in to change notification settings - Fork 82
Open
Description
Describe the bug
cargo-deny is reporting
error[unmaintained]: rustls-pemfile is unmaintained
┌─ /Users/jayvdb/work/xxx/Cargo.lock:280:1
│
280 │ rustls-pemfile 1.0.4 registry+https://github.com/rust-lang/crates.io-index
│ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ unmaintained advisory detected
│
├ ID: RUSTSEC-2025-0134
├ Advisory: https://rustsec.org/advisories/RUSTSEC-2025-0134
├ The rustls-pemfile crate is no longer maintained. The repository has been archived since August
2025, and users are encouraged to depend directly on the underlying PEM parsing code included
in rustls-pki-types since 1.9.0. The latest version of rustls-pemfile is in fact a thin wrapper
around the same code used in rustls-pki-types, so migrating should be straightforward.
The new API is represented by the [`PemObject`][PemObject] trait, which provides methods for
reading a single or multiple PEM objects from a file or byte slice.
[PemObject]: https://docs.rs/rustls-pki-types/latest/rustls_pki_types/pem/trait.PemObject.html
├ Announcement: https://github.com/rustls/pemfile/issues/61
├ Solution: No safe upgrade is available!
├ rustls-pemfile v1.0.4
└── reqwest v0.11.27
├── cherrybomb-engine v0.1.2
...
advisories FAILED, bans ok, licenses ok, sources ok
Desktop (please complete the following information):
all
Additional context
Metadata
Metadata
Assignees
Labels
No labels