Skip to content

Commit

Permalink
RUSTSEC-2016-0005: add note about rust-crypto vs RustCrypto
Browse files Browse the repository at this point in the history
The `rust-crypto` crate and RustCrypto org have confusingly similar
names, which has caused confusion about this advisory in practice:

https://www.reddit.com/r/rust/comments/e29sxc/ann_rustcryptoaead_v020_heapless_symmetric_aead/f8ujyxm/

This commit adds a small note to disambiguate them and note that
RustCrypto-the-GitHub-org is still maintained.
  • Loading branch information
tarcieri committed Jan 19, 2020
1 parent 3aa5df1 commit e30a06a
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions crates/rust-crypto/RUSTSEC-2016-0005.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,10 @@ description = """
The `rust-crypto` crate has not seen a release or GitHub commit since 2016,
and its author is unresponsive.
*NOTE: The (old) `rust-crypto` crate (with hyphen) should not be confused with
similarly named (new) [RustCrypto GitHub Org] (without hyphen). The GitHub Org
is actively maintained.*
We recommend you switch to one of the following crates instead, depending on
which algorithms you need:
Expand Down

0 comments on commit e30a06a

Please sign in to comment.