tokio-rs / tracing

Application level tracing for Rust.
https://tracing.rs
MIT License
5.5k stars 722 forks source link

RUSTSEC-2021-0127: serde_cbor is unmaintained #1762

Open github-actions[bot] opened 2 years ago

github-actions[bot] commented 2 years ago

serde_cbor is unmaintained

Details
Status unmaintained
Package serde_cbor
Version 0.11.2
URL https://github.com/pyfisch/cbor
Date 2021-08-15

The serde_cbor crate is unmaintained. The author has archived the github repository.

Alternatives proposed by the author:

ciborium minicbor

See advisory page for additional details.

hawkw commented 2 years ago

what in our dependency tree is using serde-cbor??

hawkw commented 2 years ago

ah, it is a transitive dependency via......... .......... .......... .......... ..........the benchmarking library 🙃

:; cargo tree -p serde_cbor -i
serde_cbor v0.11.2
└── criterion v0.3.5
    [dev-dependencies]
    ├── tracing v0.2.0 (/home/eliza/Code/tracing/tracing)
    │   ├── tracing-error v0.2.0 (/home/eliza/Code/tracing/tracing-error)
    │   │   [dev-dependencies]
    │   │   └── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   ├── tracing-flame v0.2.0 (/home/eliza/Code/tracing/tracing-flame)
    │   │   [dev-dependencies]
    │   │   └── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   ├── tracing-futures v0.3.0 (/home/eliza/Code/tracing/tracing-futures)
    │   │   └── tracing-tower v0.1.0 (/home/eliza/Code/tracing/tracing-tower)
    │   │       [dev-dependencies]
    │   │       └── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   │   [dev-dependencies]
    │   │   ├── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   │   └── tracing-subscriber v0.3.0 (/home/eliza/Code/tracing/tracing-subscriber)
    │   │       ├── tracing-appender v0.2.0 (/home/eliza/Code/tracing/tracing-appender)
    │   │       │   [dev-dependencies]
    │   │       │   └── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   │       ├── tracing-error v0.2.0 (/home/eliza/Code/tracing/tracing-error) (*)
    │   │       ├── tracing-flame v0.2.0 (/home/eliza/Code/tracing/tracing-flame) (*)
    │   │       ├── tracing-journald v0.2.0 (/home/eliza/Code/tracing/tracing-journald)
    │   │       │   [dev-dependencies]
    │   │       │   └── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   │       └── tracing-opentelemetry v0.15.0 (/home/eliza/Code/tracing/tracing-opentelemetry)
    │   │           [dev-dependencies]
    │   │           └── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   │       [dev-dependencies]
    │   │       ├── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   │       └── tracing-macros v0.1.0 (/home/eliza/Code/tracing/tracing-macros)
    │   ├── tracing-macros v0.1.0 (/home/eliza/Code/tracing/tracing-macros)
    │   ├── tracing-opentelemetry v0.15.0 (/home/eliza/Code/tracing/tracing-opentelemetry) (*)
    │   ├── tracing-subscriber v0.3.0 (/home/eliza/Code/tracing/tracing-subscriber) (*)
    │   └── tracing-tower v0.1.0 (/home/eliza/Code/tracing/tracing-tower) (*)
    │   [dev-dependencies]
    │   ├── tracing-appender v0.2.0 (/home/eliza/Code/tracing/tracing-appender) (*)
    │   ├── tracing-attributes v0.2.0 (proc-macro) (/home/eliza/Code/tracing/tracing-attributes)
    │   │   └── tracing v0.2.0 (/home/eliza/Code/tracing/tracing) (*)
    │   │   [dev-dependencies]
    │   │   └── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   ├── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   ├── tracing-journald v0.2.0 (/home/eliza/Code/tracing/tracing-journald) (*)
    │   ├── tracing-log v0.2.0 (/home/eliza/Code/tracing/tracing-log)
    │   │   ├── tracing-opentelemetry v0.15.0 (/home/eliza/Code/tracing/tracing-opentelemetry) (*)
    │   │   └── tracing-subscriber v0.3.0 (/home/eliza/Code/tracing/tracing-subscriber) (*)
    │   │   [dev-dependencies]
    │   │   ├── tracing-examples v0.0.0 (/home/eliza/Code/tracing/examples)
    │   │   └── tracing-subscriber v0.3.0 (/home/eliza/Code/tracing/tracing-subscriber) (*)
    │   └── tracing-subscriber v0.3.0 (/home/eliza/Code/tracing/tracing-subscriber) (*)
    ├── tracing-opentelemetry v0.15.0 (/home/eliza/Code/tracing/tracing-opentelemetry) (*)
    └── tracing-subscriber v0.3.0 (/home/eliza/Code/tracing/tracing-subscriber) (*)