Skip to content

chore(deps): rustls-pemfile RUSTSEC-2025-0134 unmaintained — track qdrant-client update #2347

@bug-ops

Description

@bug-ops

Advisory

RUSTSEC-2025-0134: rustls-pemfile is unmaintained.

Dependency Chain

qdrant-client 1.17.0 → tonic 0.12.3 → rustls-pemfile 2.2.0

This is a transitive dependency — Zeph does not depend on rustls-pemfile directly.

Impact

Severity: Low (unmaintained, not vulnerable). cargo deny check advisories fails with this warning.

Action

Monitor qdrant-client for updates that pull in a maintained alternative. No direct code change needed in Zeph.

When qdrant-client releases a version that eliminates this dependency, upgrade and verify.

Metadata

Metadata

Assignees

Labels

P3Research — medium-high complexity

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions