Package: rust-serde-yml
Severity: serious
(I will be cloning this bug against rust-libyml once I have a bug number)
rust-serde-yml is a fork of rust-serde-yaml and rust-libyml is
a fork of rust-unsafe-libyaml.
Serious concerns have been raised about the quality of code in rust-serde-yml.
https://x.com/davidtolnay/status/1883906113428676938
https://www.reddit.com/r/rust/comments/1ibdxf9/beware_of_this_guy_making_slop_crates_with_ai/
Even worse concerns have been raised about code in rust-libyml
https://x.com/mycoliza/status/1883974721143980353
Furthermore the maintainer of these forks has disabled issue tracking
on the repositories, so these issues cannot be reported where someone
ie likely to see them.
I don't think these packages should be in a Debian release at this time.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (2 / 14) |
Uptime: | 151:17:22 |
Calls: | 10,383 |
Files: | 14,054 |
Messages: | 6,417,800 |