Skip to content

deps: unmaintained rustls-pemfile via qdrant-client → tonic (RUSTSEC-2025-0134) #1846

@bug-ops

Description

@bug-ops

Summary

cargo deny check advisories reports RUSTSEC-2025-0134: rustls-pemfile v2.2.0 is unmaintained.

Dependency chain

qdrant-client v1.17.0 → tonic v0.12.3 → rustls-pemfile v2.2.0

Status

  • Not a vulnerability — unmaintained crate advisory only
  • No safe upgrade available (transitive dep)
  • Resolution requires either: qdrant-client updating tonic, or tonic 0.13+ adoption
  • rustls-pki-types >= 1.9.0 includes the PEM parsing code directly (no rustls-pemfile needed)

Action required

Monitor qdrant-client releases; upgrade when a version with tonic ≥ 0.13 is available (uses rustls-pki-types directly).

Priority

Low — cosmetic advisory, no active vulnerability.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesDependency updatessecuritySecurity-related issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions