iotaledger / iotaledger/product-core
RUSTSEC-2025-0134: rustls-pemfile is unmaintained
- Dominant language
- Rust
- Stars
- 0
- Forks
- 2
- Avg merge
- 1h 29m
- Merged PRs (30d)
- 3
Description
> rustls-pemfile is unmaintained
| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unmaintained |
| Package | `rustls-pemfile` |
| Version | `2.2.0` |
| URL | [https://github.com/rustls/pemfile/issues/61](https://github.com/rustls/pemfile/issues/61) |
| Date | 2025-11-28 |
The rustls-pemfile crate is no longer maintained. The repository has been archived since August
2025, and users are encouraged to depend directly on the underlying PEM parsing code included
in rustls-pki-types since 1.9.0. The latest version of rustls-pemfile is in fact a thin wrapper
around the same code used in rustls-pki-types, so migrating should be straightforward.
The new API is represented by the [`PemObject`][PemObject] trait, which provides methods for
reading a single or multiple PEM objects from a file or byte slice.
[PemObject]: https://docs.rs/rustls-pki-types/latest/rustls_pki_types/pem/trait.PemObject.html
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2025-0134.html) for additional details.
Contributor guide
Research direction
Start by locating where the project depends on or uses rustls-pemfile 2.2.0. Review the rustls-pki-types PemObject API described in the issue and migrate those usages; done means rustls-pemfile is no longer required and the project’s existing checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Refactor
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100