[Pkg-rust-maintainers] Bug#1139958: rust-http-types: RUSTSEC-2026-0174: Authorization::value and WwwAuthenticate::value can violate ASCII invariants
Peter Green
plugwash at debian.org
Tue Jun 16 02:49:56 BST 2026
>> The http-types crate is unmaintained and the issue is unlikely to be
>> fixed.
>
> Given the last statement this is more about tracking.
>
> Can the package OTOH be worked towards beeing removed?
Reverse dependencies seem to be async-h1 and http-cache.
I asked weepingclown about removal of http-types and async-h1
5 months ago and he said. "they all fall under the zellij tree,
so I'll need to keep them."
http-cache seems to be a recent intoduction by capitol. It looks
like http-types support is optional so perhaps we can patch it
out.
ccing weepingclown and capitol for their opinions.
More information about the Pkg-rust-maintainers
mailing list