Skip to content

Switch to tiberius-ng (maintained successor; fixes open RustSec TLS advisories) - #5

Closed
MattJackson wants to merge 1 commit into
LuigimonSoft:masterfrom
MattJackson:switch-to-tiberius-ng
Closed

MattJackson wants to merge 1 commit into
LuigimonSoft:masterfrom
MattJackson:switch-to-tiberius-ng

Conversation

@MattJackson

Copy link
Copy Markdown

Hi — thanks for maintaining rquery-orm.

The tiberius crate (0.12) is effectively unmaintained — issues and PRs have gone unanswered, and it currently ships open RustSec advisories in its TLS path (cert-verification issues RUSTSEC-2026-0098 / -0099 / -0104, plus an h2 advisory). Anything depending on it inherits those with no upstream fix available.

I've taken over maintenance as tiberius-ng — a standalone continuation with full history and all original contributors preserved (Apache-2.0, same license). It resolves those advisories and is a drop-in: it keeps [lib] name = "tiberius", so this PR is a one-line Cargo.toml change (Cargo's package = "tiberius-ng" rename) with zero source changes.

I compiled rquery-orm against tiberius-ng 0.13 with the exact feature set it enables — all green. CI here should confirm.

Completely understand if you'd rather wait and watch the project first — happy to answer questions or help with anything. Either way, wanted to flag the security angle since it affects your users today.

— Matthew

Repoints the tiberius dependency to the maintained tiberius-ng fork via
Cargo's package rename; `tiberius::` paths and `tiberius/<feature>`
references keep working with no source changes. Verified rquery-orm compiles
against tiberius-ng 0.13 with the feature set it enables.

tiberius 0.12 is unmaintained and ships open RustSec cert-verification
advisories; tiberius-ng 0.13 fixes them and keeps [lib] name = "tiberius".
@MattJackson

Copy link
Copy Markdown
Author

Update — and apologies for the extra notification.

Since I opened this, the tiberius maintainers have brought me on as a maintainer of the upstream project (tiberius-rs/tiberius), and I'm merging the tiberius-ng work directly upstream. So the maintained driver stays under the original tiberius crate — no dependency switch needed after all.

Closing this as no longer necessary. Thanks for your time, and apologies for the noise.

@MattJackson MattJackson closed this Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant