[Pkg-rust-maintainers] Bug#1089875: RM: rust-users -- ROM; Unmaintained upstream, security bug

NoisyCoil noisycoil at tutanota.com
Sat Dec 14 11:43:30 GMT 2024


Package: ftp.debian.org
Severity: normal
Tags: security
X-Debbugs-Cc: rust-users at packages.debian.org, noisycoil at tutanota.com, Debian Security Team <team at security.debian.org>
Control: affects -1 + src:rust-users
User: ftp.debian.org at packages.debian.org
Usertags: remove

Hello,

On behalf of the Rust Team, please remove src:rust-users from unstable and
testing. It is unmaintained upstream as reported in security Bug#1051808,
and has a pending security advisory, RUSTSEC-2023-0059 [1].

At the time of writing, rust-users has one rdep left, rust-coreutils. Its
maintainer agreed to fix it in the very near future (and to go forward with
this removal request) [2], so by the time you will read this there may not be
rdeps left. Just in case, I opened an RC bug on rust-coreutils (Bug#1089872)
to make sure that removal of rust-users won't introduce further breakage.

Thank you!


[1] https://rustsec.org/advisories/RUSTSEC-2023-0059.html
[2] https://salsa.debian.org/rust-team/debcargo-conf/-/issues/99



More information about the Pkg-rust-maintainers mailing list