unicode-org / icu4x

Solving i18n for client-side and resource-constrained environments.
https://icu4x.unicode.org
Other
1.29k stars 166 forks source link

Reliance on archived project partial-min-max #4764

Open SimonClark opened 3 months ago

SimonClark commented 3 months ago

In going through my org's security review, a concern was raised over the reliance of utils/bies on the partial-min-max crate. https://github.com/fitzgen/fart/tree/master does not have a well formed license, and has been archived.

Any chance we can remove this as a dependency? Would it be most expeditious for me to submit an MR to do that?

sffc commented 3 months ago

Hi! Happy to entertain a pull request to remove the dependency. Note that the bies util crate is not currently a dependency of icu4x library code, but it might be in the future.