[Pkg-rust-maintainers] Bug#1051808: Bug#1051808: rust-users: RUSTSEC-2023-0059

Blair Noctis n at sail.ng
Mon Nov 27 10:18:50 GMT 2023


On Wed, 13 Sep 2023 04:07:24 +0100 Peter Green <plugwash at debian.org> wrote:
> > rust-users is currently unmaintained upstream.
> > 
> > In a fork a proposed patch can be found.
> > 
> > What is the rust-users situation with respect of Debian as it is
> > unmantained upstream?
> 
> So we have two options, patch it or move away from it to a fork
> 
> The crate "uzers" which is a fork of this crate was recently
> uploaded to Debian and I have just uploaded version 0.11.3 of
> it. I believe that said version includes a fix for this issue.
> 
> Uzers is listed as an alternative on the rustsec entry, but at
> least so-far there doesn't seem to have been a whole lot of uptake.
> crates.io only lists one reverse dependency of said fork, which
> is itself a fork of exa.
> 

Currently packaged downstreams are pam, sniffglue, and please (packaged as
pleaser). I've sent pull requests to [pam] & [sniffglue] and opened an issue for
[please]. Hopefully we can soon see them migrate.

pam: https://github.com/1wilkens/pam/pull/39
sniffglue: https://github.com/kpcyrd/sniffglue/pull/124

-- 
Sdrager,
Blair Noctis

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 228 bytes
Desc: OpenPGP digital signature
URL: <http://alioth-lists.debian.net/pipermail/pkg-rust-maintainers/attachments/20231127/9ddb524c/attachment-0001.sig>


More information about the Pkg-rust-maintainers mailing list