Skip to content

Add support for custom JWS algorithms (#1410) #7

Add support for custom JWS algorithms (#1410)

Add support for custom JWS algorithms (#1410) #7

GitHub Actions / Security audit succeeded Sep 17, 2024 in 0s

Security advisories found

4 unmaintained, 1 other

Details

Warnings

RUSTSEC-2021-0139

ansi_term is Unmaintained

Details
Status unmaintained
Package ansi_term
Version 0.12.1
URL ogham/rust-ansi-term#72
Date 2021-08-18

The maintainer has advised that this crate is deprecated and will not receive any maintenance.

The crate does not seem to have much dependencies and may or may not be ok to use as-is.

Last release seems to have been three years ago.

Possible Alternative(s)

The below list has not been vetted in any way and may or may not contain alternatives;

Dependency Specific Migration(s)

RUSTSEC-2021-0065

anymap is unmaintained.

Details
Status unmaintained
Package anymap
Version 0.12.1
URL chris-morgan/anymap#37
Date 2021-05-07

The anymap crate does not appear to be maintained, and the most recent
published version 0.12.1 includes a soundness bug. This has been
fixed a few years ago, but
was never released.

RUSTSEC-2021-0141

dotenv is Unmaintained

Details
Status unmaintained
Package dotenv
Version 0.15.0
URL dotenv-rs/dotenv#74
Date 2021-12-24

dotenv by description is meant to be used in development or testing only.

Using this in production may or may not be advisable.

Alternatives

The below may or may not be feasible alternative(s):

RUSTSEC-2024-0370

proc-macro-error is unmaintained

Details
Status unmaintained
Package proc-macro-error
Version 1.0.4
URL https://gitlab.com/CreepySkeleton/proc-macro-error/-/issues/20
Date 2024-09-01

proc-macro-error's maintainer seems to be unreachable, with no commits for 2 years, no releases pushed for 4 years, and no activity on the GitLab repo or response to email.

proc-macro-error also depends on syn 1.x, which may be bringing duplicate dependencies into dependant build trees.

Possible Alternative(s)