Closed sassman closed 11 months ago
Hi @sassman , thanks for reporting this. We'll consider switching over to the maintained rustls-webpki
fork.
Filed internally as 214672.
Hi @cwaldren-ld, thanks for your swift response, do you have any timeline on having a patch ready?
Hello @sassman, sorry for the slightly delayed response. After discussing with the Rust engineers on the team, the current plan is to fix this all together when https://github.com/hyperium/hyper releases their 1.0 crate (They had the rc4 release a couple of months ago), as there are a lot of breaking changes and will require the Rust SDK also take a major version bump.
since hyper v1 is releasing today is there a timeline for the patch ?
Well funnily enough, I decided the other day to not wait for that release, and just got our changes released now. 🤦🏼
Anyway, 0.12.0 is out with updated dependencies but still pre v1-hyper.
the problematic package is
webpki@0.21.4
the tree goes as:The whole log from
cargo deny check advisories