Closed
Description
Running cargo audit
on https://github.com/google/OpenSK reveals that linked_list_allocator
depends on spin
, which is no longer actively maintained (advisory RUSTSEC-2019-0031).
Crate: spin
Title: spin is no longer actively maintained
Date: 2019-11-21
URL: https://rustsec.org/advisories/RUSTSEC-2019-0031
Dependency tree:
spin 0.5.2
└── linked_list_allocator 0.6.6
└── libtock 0.1.0
Full Travis-CI log: https://travis-ci.org/google/OpenSK/builds/646900743.
It seems that spin is an optional dependency and active when the use_spin
feature is enabled (which is by default).
The advisory suggests to migrate to https://crates.io/crates/lock_api or https://crates.io/crates/conquer-once (according to the advisory, both should support no_std
).
Metadata
Metadata
Assignees
Labels
No labels