theupdateframework / theupdateframework/rust-tuf

RUSTSEC-2019-0031: spin is no longer actively maintained

Open
#261 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
198
Forks
39
Avg merge
9h 19m
Merged PRs (30d)
2

Description

spin is no longer actively maintained

Details
Status unmaintained
Package spin
Version 0.5.2
URL https://github.com/mvdnes/spin-rs/commit/7516c80
Date 2019-11-21
Unaffected versions > 0.5.2

The author of the spin crate does not have time or interest to maintain it.

Consider lock_api (a subproject of
parking_lot) as an alternative which also supports no_std environments.

See advisory page for additional details.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the project's dependency declarations to find whether spin 0.5.2 is used. Compare upgrading it with the lock_api alternative described in the advisory, then run the existing test suite; done means the unmaintained dependency is no longer used and the tests pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.