theupdateframework / theupdateframework/rust-tuf
RUSTSEC-2019-0031: spin is no longer actively maintained
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 198
- Forks
- 39
- Avg merge
- 9h 19m
- Merged PRs (30d)
- 2
Description
spin is no longer actively maintained
| Details | |
|---|---|
| Status | unmaintained |
| Package | spin |
| Version | 0.5.2 |
| URL | https://github.com/mvdnes/spin-rs/commit/7516c80 |
| Date | 2019-11-21 |
| Unaffected versions | > 0.5.2 |
The author of the spin crate does not have time or interest to maintain it.
Consider lock_api (a subproject of
parking_lot) as an alternative which also supports no_std environments.
See advisory page for additional details.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the project's dependency declarations to find whether spin 0.5.2 is used. Compare upgrading it with the lock_api alternative described in the advisory, then run the existing test suite; done means the unmaintained dependency is no longer used and the tests pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100