RUSTSEC-2025-0010: Versions of *ring* prior to 0.17 are unmaintained.
- Dominant language
- Rust
- Stars
- 0
- Forks
- 0
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 3
Description
> Versions of *ring* prior to 0.17 are unmaintained.
| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unmaintained |
| Package | `ring` |
| Version | `0.16.20` |
| URL | [https://github.com/briansmith/ring/discussions/2450](https://github.com/briansmith/ring/discussions/2450) |
| Date | 2025-03-05 |
*ring* 0.16.20 was released over 4 years ago and isn't maintained, tested, etc.
Additionally, the project's general policy is to only patch the latest release,
which is 0.17.12 now. It will be difficult for anybody to backport future fixes
to versions earlier than 0.17.10 due to license changes.
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2025-0010.html) for additional details.
Contributor guide
No contributing guide indexed for this repository
Research direction
No file or test is named. Start by locating the Rust dependency declaration for ring and read the linked RustSec advisory; done means the project no longer selects the unmaintained 0.16.20 release and its dependency checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100