Skip to content

Conversation

@jayvdb
Copy link
Contributor

@jayvdb jayvdb commented Nov 16, 2025

Closes #2211

@dhardy
Copy link
Contributor

dhardy commented Nov 17, 2025

Can advisories target specific versions?

There's a chance we re-launch rand_os for rand_core v0.10.

@paolobarbolini
Copy link
Contributor

Can advisories target specific versions?

There's a chance we re-launch rand_os for rand_core v0.10.

In that case it wouldn't make sense to have an unmaintained advisory.

@jayvdb
Copy link
Contributor Author

jayvdb commented Nov 17, 2025

Advisories can be rescinded.

@jayvdb
Copy link
Contributor Author

jayvdb commented Nov 17, 2025

IMO it is all the more important to get this advisory out, so current users of rand_os upgrade before a new rand_os appears.

Or will the new rand_os have the same API as the old one, this providing a viable upgrade path for users of the old rand_os?

@dhardy
Copy link
Contributor

dhardy commented Nov 17, 2025

unmaintained advisory

Take a look at the download stats; the high usage doesn't even apply to the latest version (0.2.x). So whether or not we release a new version is entirely irrelevant to the high download rate of 0.1.x.

Or will the new rand_os have the same API as the old one, this providing a viable upgrade path for users of the old rand_os?

It would require the latest rand_core so be incompatible.

@jayvdb
Copy link
Contributor Author

jayvdb commented Nov 17, 2025

Right, an advisory will assist in reducing usage of 0.1.x as well as 0.2.x.

@djc djc merged commit c859f16 into rustsec:main Nov 18, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

rand_os was deprecated 5.5 years ago - crates.io still reports many daily downloads

4 participants