LinusCDE / chessmarkable

Chess for the reMarkable using the rust pleco lib
MIT License
104 stars 8 forks source link

RUSTSEC-2021-0140: rusttype is Unmaintained #20

Closed github-actions[bot] closed 2 years ago

github-actions[bot] commented 2 years ago

rusttype is Unmaintained

Details
Status unmaintained
Package rusttype
Version 0.9.2
URL https://gitlab.redox-os.org/redox-os/rusttype/-/issues/148
Date 2021-04-01

The maintainer has adviced this crate is deprecated and will not receive any maintenance.

The maintainer has further advised to migrate over to ab_glyph.

Last release seems to have been over two years ago.

Possible Alternative(s)

The below list has not been vetted in any way and may or may not contain alternatives;

See advisory page for additional details.

LinusCDE commented 2 years ago

This is a dependency of libremarkable. Though I also maintain that as well.

I think the migration to a newer font drawing lib was discussed a while ago already by @bkirwi if I'm not mistaken.

So we might use that as an opportunity to transition to a newer lib. Either the successor by the same author, ab_glyph, or whatever was deemed better back then.

This is not a strict security issue. Maybe a performance one. So it's not really not a prio and not directly affecting chesssmarkable. Closing this for now.