You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've noticed you have yanked all older versions of monocypher-rs, but this is not always considered a good practice in rust.
ring used to do it, but it caused lots of discussions, resulting in rust-lang/crater moving from ring to openssl (rust-lang/crater#394) and ring starting yanking only known-vulnerable versions. See this comment from pietroalbini (member of many rust teams). It's a bit subjective, but my personal opinion is similar, crates should be yanked only when there's a semver compatible release available.
Well, it's so hard to know what are the current best practices, I think I only know about this because I've been bitten by the transitive yanked ring before ;)
Uh oh!
There was an error while loading. Please reload this page.
I've noticed you have yanked all older versions of monocypher-rs, but this is not always considered a good practice in rust.
ring
used to do it, but it caused lots of discussions, resulting in rust-lang/crater moving from ring to openssl (rust-lang/crater#394) and ring starting yanking only known-vulnerable versions. See this comment from pietroalbini (member of many rust teams). It's a bit subjective, but my personal opinion is similar, crates should be yanked only when there's a semver compatible release available.Related discussions:
On an unrelated notes, I'm contributing a little to this crate but I don't wish to give too much maintenance burden, sorry if I am...
The text was updated successfully, but these errors were encountered: