—
RUSTSEC-2026-0192
`ttf-parser` is unmaintained
Details
The author of `ttf-parser` has stated that the crate is unmaintained and will not receive further fixes (see the referenced issue).
## Alternative(s)
- [`skrifa`](https://crates.io/crates/skrifa), an actively maintained TrueType and OpenType font parsing crate, part of the Google Fonts "oxidize" (`fontations`) project.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io / ttf-parser
Introduced in:
0.0.0-0 No fixed version published yet for ttf-parser. Pin to a known-safe version or switch to an alternative.