Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

surf seems to be unmaintained #1471

Closed
djc opened this issue Nov 25, 2022 · 3 comments
Closed

surf seems to be unmaintained #1471

djc opened this issue Nov 25, 2022 · 3 comments
Labels
Unmaintained Informational / Unmaintained

Comments

@djc
Copy link
Contributor

djc commented Nov 25, 2022

The surf HTTP client seems to be unmaintained. I reached out and it doesn't look good. It depends on the latest released version of http-types, which depends on an old version of cookie which in turns depends on the unmaintained stdweb, an old version of aes-gcm which in turns has a number of unmaintained dependencies. There's an issue in http-types to get a new release out but not much movement there.

surf itself additionally still depends on rustls 0.18, while 0.19 was released two years ago.

@pinkforest
Copy link
Contributor

Commented here: http-rs/surf#352 (comment)

The maintainer has indicated willingness to merge any security fixes and per our policy we reserve unmaintained for completely unreachable maintainers or where the maintainer explicitly wishes us to flag it.

An action here might be feasible to flag old versions of rustls and then that will light up anything downstream if feasible ?

@pinkforest pinkforest added Unmaintained Informational / Unmaintained Waiting-Maintainer Waiting-Maintainer labels Nov 25, 2022
@pinkforest
Copy link
Contributor

Can't do anything here since the maintainer has said they will fix any security issue and we take the maintainer's word.

Also have offered to mark old versions of rustls unmaintained as the dependencies further up can be used to light up things

Please let us know if you would like us to do that and we can do that to ensure any downstream dependencies complain if they use the old rustls version.

@djc
Copy link
Contributor Author

djc commented Sep 7, 2023

There's an explicit comment from the maintainer that it should be considered unmaintained:

http-rs/surf#352 (comment)

Is that enough to warrant an informational advisory for this crate?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Unmaintained Informational / Unmaintained
Projects
None yet
Development

No branches or pull requests

2 participants