Skip to content

Paste is dead, long live Pastey #4118

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

martinfrances107
Copy link
Contributor

The crate paste is no longer maintained, and has a replacement. On that basis only my IDE is reporting "paste" as a security hazard.

"pastey is the fork of paste and is aimed to be a drop-in replacement with additional features for paste crate" https://crates.io/crates/pastey

The crate paste is no longer maintained, and has a replacement.
On that basis only my IDE is reporting "paste" as a security hazard.

"pastey is the fork of paste and is aimed to be a drop-in replacement with additional features for paste crate"
<https://crates.io/crates/pastey>
@martinfrances107
Copy link
Contributor Author

martinfrances107 commented Jun 28, 2025

For review purposes, I want to bring a potential critisism of this patch to the fore.

"paste" has a really high volume of daily downlaods ~500,000 and I expect a steady fall from here on.

"pastey" is ramping up quickly but is currently peak is only lowly 3,000 daily downloads.

If a serious security problem becomes unveiled in "paste" the stock answer will always be move to "pastey" we will fix it there..

My question is "what is the resonable response if a new security flaw appears in the 'pastey' crate" ... the low volume of daily downloads means the community is far less likley to see it, report it.

Anyway, I just thought I should mention the hazard.

@gbj
Copy link
Collaborator

gbj commented Jun 28, 2025

See discussion in #3685

@martinfrances107
Copy link
Contributor Author

From the discussion mentioned

Anyway, just wanted to post a note to say I'd seen this, and that my plan is to wait and see where the ecosystem lands.

A resonable attitude ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants