[GH-ISSUE #963] spin transitive dependency is no longer maintained #577

Closed
opened 2026-03-15 23:15:33 +03:00 by kerem · 5 comments
Owner

Originally created by @bluejekyll on GitHub (Dec 18, 2019).
Original GitHub issue: https://github.com/hickory-dns/hickory-dns/issues/963

This is currently causing cargo audit to fail.

See: https://github.com/briansmith/ring/issues/921

And the advisory: https://rustsec.org/advisories/RUSTSEC-2019-0031

Originally created by @bluejekyll on GitHub (Dec 18, 2019). Original GitHub issue: https://github.com/hickory-dns/hickory-dns/issues/963 This is currently causing `cargo audit` to fail. See: https://github.com/briansmith/ring/issues/921 And the advisory: https://rustsec.org/advisories/RUSTSEC-2019-0031
Author
Owner

@djc commented on GitHub (Oct 17, 2020):

Note that there's a new (semver-incompatible) spin release, from a new maintainer. So that maybe picked up by ring.

<!-- gh-comment-id:711021041 --> @djc commented on GitHub (Oct 17, 2020): Note that there's a new (semver-incompatible) spin release, from a new maintainer. So that maybe picked up by *ring*.
Author
Owner

@bluejekyll commented on GitHub (Oct 17, 2020):

If that’s the case, then we can remove the explicit allow here: https://github.com/bluejekyll/trust-dns/blob/main/Makefile.toml#L271

<!-- gh-comment-id:711021576 --> @bluejekyll commented on GitHub (Oct 17, 2020): If that’s the case, then we can remove the explicit allow here: https://github.com/bluejekyll/trust-dns/blob/main/Makefile.toml#L271
Author
Owner
<!-- gh-comment-id:711022759 --> @djc commented on GitHub (Oct 17, 2020): See also https://github.com/briansmith/ring/pull/1053, https://github.com/mvdnes/spin-rs/issues/79, https://github.com/RustSec/advisory-db/pull/424.
Author
Owner

@trinity-1686a commented on GitHub (May 30, 2021):

--ignore=RUSTSEC-2019-0031 was removed from Makefile.toml when treating unrelated audit issue in 6cbc7f5886

<!-- gh-comment-id:851080505 --> @trinity-1686a commented on GitHub (May 30, 2021): `--ignore=RUSTSEC-2019-0031` was removed from Makefile.toml when treating unrelated audit issue in 6cbc7f588641816cb82307e5e37947ba3aa2b8c7
Author
Owner

@bluejekyll commented on GitHub (May 31, 2021):

Thanks for following up!

<!-- gh-comment-id:851090391 --> @bluejekyll commented on GitHub (May 31, 2021): Thanks for following up!
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hickory-dns#577
No description provided.