iotaledger / iotaledger/product-core

RUSTSEC-2025-0134: rustls-pemfile is unmaintained

Open
#80 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
0
Forks
2
Avg merge
1h 29m
Merged PRs (30d)
3

Description

> rustls-pemfile is unmaintained

| Details | |
| ------------------- | ---------------------------------------------- |
| Status | unmaintained |
| Package | `rustls-pemfile` |
| Version | `2.2.0` |
| URL | [https://github.com/rustls/pemfile/issues/61](https://github.com/rustls/pemfile/issues/61) |
| Date | 2025-11-28 |

The rustls-pemfile crate is no longer maintained. The repository has been archived since August
2025, and users are encouraged to depend directly on the underlying PEM parsing code included
in rustls-pki-types since 1.9.0. The latest version of rustls-pemfile is in fact a thin wrapper
around the same code used in rustls-pki-types, so migrating should be straightforward.

The new API is represented by the [`PemObject`][PemObject] trait, which provides methods for
reading a single or multiple PEM objects from a file or byte slice.

[PemObject]: https://docs.rs/rustls-pki-types/latest/rustls_pki_types/pem/trait.PemObject.html

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2025-0134.html) for additional details.

Contributor guide

Open the contributing guide

Research direction

Start by locating where the project depends on or uses rustls-pemfile 2.2.0. Review the rustls-pki-types PemObject API described in the issue and migrate those usages; done means rustls-pemfile is no longer required and the project’s existing checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Refactor
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.