Advisories for Cargo/Serde_yml package

2025

serde_yml crate is unsound and unmaintained

Using serde_yml::ser::Serializer.emitter can cause a segmentation fault, which is unsound. The GitHub project for serde_yml was archived after unsoundness issues were raised. If you rely on this crate, it is highly recommended switching to a maintained alternative.