Consider 'cargo yank'
Hi,
GNOME Security received the following issue report regarding this repo:
libolm should not be used anymore - matrix deprecated it as it was attracting CVEs and it was never supposed to be used in production - they re-wrote it in Rust two years ago
https://gitlab.matrix.org/matrix-org/olm/-/blob/master/lib/crypto-algorithms/README.md
Affected repo: https://gitlab.gnome.org/BrainBlasted/olm-sys
https://crates.io/crates/olm-sys & https://crates.io/crates/olm-rs
Please consider using cargo yank on those crates so nobody uses it
Soatok has some refined details: https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/
(Originally reported here.)