commercialhaskell / stackage

Stable Haskell package sets: vetted consistent packages from Hackage
https://www.stackage.org/
MIT License
530 stars 805 forks source link

deprecating cryptonite #7474

Open juhp opened 4 months ago

juhp commented 4 months ago

These are packages which have not migrated yet to crypton

cryptonite (Vincent Hanquez) (not present) depended on by:

My understanding is that crypton should be a maintained drop-in replacement for the unmaintained (and less secure) cryptonite so all that should be needed to update your dependencies on cryptonite to crypton instead

juhp commented 4 months ago

For more context see haskell/security-advisories#187 and #7336

It would be really great if some would step to forking/replacing memory too

prikhi commented 4 months ago

awesome thanks, gemini-exports fixed in v0.1.0.2

khibino commented 4 months ago

I uploaded protocol-radius-0.0.1.2 with change of dependency from cryptonite to crypton https://hackage.haskell.org/package/protocol-radius-0.0.1.2

istathar commented 4 months ago

Uploaded locators 0.3.0.5 changing dependency from cryptonite to crypton. Thanks for pursuing this.

pbrisbin commented 4 months ago

yesod-auth-oauth2 updated to crypton as of 0.7.3.0: https://hackage.haskell.org/package/yesod-auth-oauth2-0.7.3.0/dependencies