Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chrono is unmaintained and has a vulnerable dependency #1216

Closed
ghost opened this issue Mar 22, 2022 · 2 comments
Closed

chrono is unmaintained and has a vulnerable dependency #1216

ghost opened this issue Mar 22, 2022 · 2 comments

Comments

@ghost
Copy link

ghost commented Mar 22, 2022

someone asked about this over a month ago with no official reply. there have been some commits but no releases or fixes for reported vulnerabilities in the time dependency. there are many issues and prs for the time issue in the repo.

is it time for cargo audit to list this as unmaintained since its so widely used and not being properly cared for by the owner/maintainers?

chronotope/chrono#650

@tarcieri
Copy link
Member

tarcieri commented Mar 23, 2022

chrono is a high-profile crate so we should definitely do our due diligence. However I would agree there's a case to be made that it falls under the WIP guidelines for unmaintained crates being drafted in #1192.

I will ask for input from chrono maintainers on the linked issue in order to attempt to help determine next steps.

@tarcieri
Copy link
Member

We have confirmation on chronotope/chrono#650 that chrono is maintained. Closing this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant