FuelLabs / FuelLabs/forc

RUSTSEC-2025-0010: Versions of *ring* prior to 0.17 are unmaintained.

Open
#135 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
0
Forks
0
Avg merge
1d 22h
Merged PRs (30d)
3

Description

> Versions of *ring* prior to 0.17 are unmaintained.

| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unmaintained |
| Package | `ring` |
| Version | `0.16.20` |
| URL | [https://github.com/briansmith/ring/discussions/2450](https://github.com/briansmith/ring/discussions/2450) |
| Date | 2025-03-05 |

*ring* 0.16.20 was released over 4 years ago and isn't maintained, tested, etc.

Additionally, the project's general policy is to only patch the latest release,
which is 0.17.12 now. It will be difficult for anybody to backport future fixes
to versions earlier than 0.17.10 due to license changes.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2025-0010.html) for additional details.

Contributor guide

No contributing guide indexed for this repository

Research direction

No file or test is named. Start by locating the Rust dependency declaration for ring and read the linked RustSec advisory; done means the project no longer selects the unmaintained 0.16.20 release and its dependency checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.