Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUSTSEC-2024-0370: proc-macro-error is unmaintained #388

Open
github-actions bot opened this issue Sep 7, 2024 · 2 comments
Open

RUSTSEC-2024-0370: proc-macro-error is unmaintained #388

github-actions bot opened this issue Sep 7, 2024 · 2 comments

Comments

@github-actions
Copy link

github-actions bot commented Sep 7, 2024

proc-macro-error is unmaintained

Details
Status unmaintained
Package proc-macro-error
Version 1.0.4
URL https://gitlab.com/CreepySkeleton/proc-macro-error/-/issues/20
Date 2024-09-01

proc-macro-error's maintainer seems to be unreachable, with no commits for 2 years, no releases pushed for 4 years, and no activity on the GitLab repo or response to email.

proc-macro-error also depends on syn 1.x, which may be bringing duplicate dependencies into dependant build trees.

Possible Alternative(s)

See advisory page for additional details.

@tannaurus
Copy link
Contributor

tannaurus commented Sep 17, 2024

This appears to have silenced in main https://github.com/sigstore/sigstore-rs/pull/387/files

This that a temporary solution, do we plan on monitoring this further?

@flavio
Copy link
Member

flavio commented Sep 18, 2024

I've reported the issue to oci-spec, which is including this dependency. There's hope this is going to be addressed soon. See youki-dev/oci-spec-rs#209

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants