Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Why are almost all older versions yanked? #346

Open
TheDan64 opened this issue May 16, 2024 · 3 comments
Open

Why are almost all older versions yanked? #346

TheDan64 opened this issue May 16, 2024 · 3 comments

Comments

@TheDan64
Copy link

TheDan64 commented May 16, 2024

The vast majority of the older versions have been yanked: https://crates.io/crates/rmp-serde/versions. Surely they don't all have critical vulnerabilities that warrant this?

I can obviously use a lockfile to retrieve the yanked version, but this broke underneath my feet. I have a few libraries which don't have lockfiles per the previous rust guidelines and are depending on 0.x.y and can't be upgraded to 1.x. So these libraries just stopped working out of the blue and now require a lockfile going forward, which is concerning

@AlexGatz
Copy link

I completely agree with @TheDan64

This was pretty shocking to stumble upon.

@KillTheMule
Copy link
Contributor

0.15.5 and 0.14.4 are still available, don't those fit?

@TheDan64
Copy link
Author

TheDan64 commented May 16, 2024

Nope, am stuck on 0.13 :( 0.13.7 was just recently yanked

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants