NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2064 most downloaded on crates.io
DEPRECATED — `libyml` is unmaintained. This release is a thin compatibility shim that forwards every call to `unsafe-libyaml` (the upstream C-libyaml translation `libyml` was originally forked from). Please migrate to `unsafe-libyaml`, `yaml-rust2`, or `noyalib`.
Last release 4 months ago
29 May 2026
Ships unpredictably
gaps range from 4 weeks to 1.8 years
Most releases are documented
notes for 4 of 6 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
6 releases · first in 2024
…trigger undefined behaviour. v0.0.6 removes the vulnerable surface entirely — the entire libyml::string module is gone from the source tree alongside…
libyml is unmaintained. v0.0.6 is a thin compatibility shim
that forwards every call to the upstream
unsafe-libyaml (which
libyml was originally forked from), so existing call sites keep
working while you plan a migration.
RUSTSEC-2025-0067
flagged all libyml ≤ 0.0.5 as unsound — the
libyml::string::yaml_string_extend function had a code path
that could trigger undefined behaviour. v0.0.6 removes the
vulnerable surface entirely — the entire libyml::string
module is gone from the source tree alongside the rest of the
hand-translated C-libyaml copy, and every public function is now
re-exported from unsafe-libyaml.
cargo audit will still warn anyway because the RustSec
advisory database tracks the crate's unmaintained status rather
than code presence. See the README's "cargo audit" section
for a copy-paste .cargo/audit.toml snippet.
| Crate | Migration shape | Best fit |
|---|---|---|
unsafe-libyaml |
Drop-in upstream — rename PascalCase types/consts to snake_case / SCREAMING_SNAKE_CASE | Codebases that want to stay on the raw libyaml-shaped FFI API on a maintained backend |
yaml-rust2 |
Not FFI-shaped — YamlLoader::load_from_str returns a Yaml AST |
Users who want to drop the C-libyaml model entirely while keeping a low-level parser primitive in pure Rust |
noyalib |
Higher-level typed API (from_str::<T> / Value); pure-Rust, #![forbid(unsafe_code)] |
Users who can move from event-stream parsing to typed deserialisation |
Full mapping tables and behavioural notes:
MIGRATION.md.
src/; every public function is now re-exported fromunsafe-libyaml.libyml::api,libyml::decode, libyml::document, libyml::dumper,libyml::loader, libyml::yaml, libyml::success) retainedlibyml::memory and libyml::string retained as empty stubyaml_string_extend unsoundCargo.toml: single runtime dep on unsafe-libyaml = "0.2.11".MIGRATION.md)Most downstream code compiles unchanged against this shim. Three
deltas flow through from the upstream:
c_int → bool for boolean parametersyaml_scalar_event_initialize(..., 1, 1, …) →yaml_scalar_event_initialize(..., true, true, …)).libyml::success::Success is no longer a nameable type —.ok on return values directly.YAML_* SCREAMING_SNAKE_CASE in match arms.76 files changed, 2 449 insertions, 20 584 deletions.
One column per month.
LibYML (a fork of unsafe-libyaml)
LibYML is a Rust library for working with YAML data, forked from unsafe-libyaml. It offers a safe and efficient interface for parsing, emitting, and manipulating YAML data.
Merge pull request #4 from sebastienrousseau/feat/libyml
Full Changelog: v0.0.4...v0.0.5
LibYML (a fork of unsafe-libyaml)
This library is a fork of unsafe-libyaml, a version of libyaml translated from C to unsafe Rust with the assistance of c2rust.
This project, has been renamed to LibYML for simplicity and to avoid confusion with the original unsafe-libyaml crate which is now archived and no longer maintained.
Code Decoupling: Major refactoring to improve modularity:
document.rs and decode.rs to decouple functionality from api.rsmemory.rs for memory management functionsinternal.rs for internal helper functionsEnhanced Memory Management: Implemented dedicated functions for memory allocation, reallocation, and freeing in memory.rs
Default Trait Implementation: Added Default trait implementation for YAML types
Error Handling: Implemented consistent error handling throughout the codebase
Code Formatting: Resolved various formatting issues and addressed Clippy warnings
Documentation: Minor tweaks and versioning updates in the documentation
return statementsassert_eq! with boolean literalsyaml.rs and yaml_malloc[dependencies]
libyml = "0.0.4"Release notes are available under GitHub releases.
This library is compatible with Rust 1.60 and above.
MIT license, same as libyaml.
Full Changelog: 0.0.3...v0.0.4
LibYML (a fork of unsafe-libyaml)
This library is a fork of unsafe-libyaml, a version of libyaml translated from C to unsafe Rust with the assistance of c2rust.
This project, has been renamed to LibYML for simplicity and to avoid confusion with the original unsafe-libyaml crate which is now archived and no longer maintained.
This library is a fork of the excellent work done by David Tolnay and the maintainers of the unsafe-libyaml library.
LibYML has now evolved into a separate library with its own goals and direction in mind and does not intend to replace the original unsafe-libyaml crate.
If you are currently using unsafe-libyaml in your projects, we recommend carefully evaluating your requirements and considering the stability and maturity of the original library as well as looking at the features and improvements offered by other libraries in the Rust ecosystem.
I would like to express my sincere gratitude to David Tolnay and the unsafe-libyaml and libyaml maintainers for their valuable contributions to the Rust and C programming communities.
[dependencies]
libyml = "0.0.3"Release notes are available under GitHub releases.
This library is compatible with Rust 1.60 and above.
MIT license, same as libyaml.
LibYML for simplicity and to avoid confusion with the original unsafe-libyaml crate which is now archived and no longer maintained.Build:
Chore:
Fixes:
lib.rs for clarity.Full Changelog: https://github.com/sebastienrousseau/libyml/commits/0.0.3
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →