—
RUSTSEC-2025-0067
`libyml::string::yaml_string_extend` is unsound and unmaintained
Details
In version 0.0.4, `libyml::string::yaml_string_extend` was revised resulting in undefined behaviour, which is unsound.
The GitHub project for `libyml` was archived after unsoundness issues were raised.
If you rely on this crate, it is highly recommended switching to a maintained alternative.
## Recommended alternatives
- [`libyaml-safer`](https://crates.io/crates/libyaml-safer) - [`unsafe-libyaml-norway`](https://crates.io/crates/unsafe-libyaml-norway) - Maintained fork of `unsafe-libyaml`
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/libyml
Introduced in:
0.0.0-0No fixed version published yet for libyml. Pin to a known-safe version or switch to an alternative.