Release v0.12.2
Security Fix - Replace Unsound YAML Dependency
Replaced serde_yml (RUSTSEC-2025-0067, RUSTSEC-2025-0068) with serde_yaml_ng, a maintained fork of dtolnay's original serde_yaml. The previous serde_yml crate and its libyml dependency were flagged as unsound and unmaintained by RustSec.
Changed
Dependencies
- Replaced
serde_yml0.0.12 withserde_yaml_ng0.10.0 for YAML parsing serde_yaml_ngis a direct continuation of dtolnay'sserde_yaml, based onunsafe-libyamlinstead of the unsoundlibyml- Resolves RUSTSEC-2025-0067 (libyml unsound) and RUSTSEC-2025-0068 (serde_yml unsound/unmaintained)
cargo auditnow passes with zero warnings
Upgrade
bash
# Homebrew
brew upgrade gcop-rs
# Cargo
cargo install gcop-rs
# pip
pip install --upgrade gcop-rs