NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2042 most downloaded on crates.io
DEPRECATED — `serde_yml` is unmaintained. This release is a thin compatibility shim that forwards every call to `noyalib` (a pure-Rust, `#![forbid(unsafe_code)]` YAML library). Please migrate to `noyalib`.
Last release 4 months ago
27 May 2026
Ships unpredictably
gaps range from 1 weeks to 1.8 years
Some releases are documented
notes for 6 of 13 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
13 releases · first in 2024
0.0.13 removes the vulnerable surface entirely:
serde_yml is deprecatedThis is the final maintenance release of serde_yml. The crate is no longer under active development. 0.0.13 is a thin compatibility shim that lets existing call sites keep compiling while you migrate to one of the maintained alternatives listed below.
If you are reading this because cargo audit flagged your build, upgrading to 0.0.13 resolves RUSTSEC-2025-0068 structurally — see Security below.
# Cargo.toml
- serde_yml = "0.0"
+ serde_yml = "0.0.13"Your existing call sites compile unchanged. The compiler now emits a #[deprecated] warning at every use serde_yml::* import pointing at the migration guide. The C-FFI libyml parser is no longer in your dependency graph.
When you're ready to fully migrate, see the migration guide.
RUSTSEC-2025-0068 (also GHSA-hhw4-xg65-fp2x) flagged every serde_yml ≤ 0.0.12 as unsound — the serde_yml::ser::Serializer.emitter field could cause a segmentation fault via the C-FFI libyaml parser.
0.0.13 removes the vulnerable surface entirely:
libyml dependency is gone from the graph.serde_yml::ser::Serializer is now a re-export of a pure-Rust unit struct (pub struct Serializer;) with no emitter field — code that referenced .emitter no longer compiles, which is the desired outcome.noyalib) enforces #![forbid(unsafe_code)] workspace-wide.Verification:
cargo update -p serde_yml --precise 0.0.13
cargo tree -p serde_yml | grep libyml # → no outputThe RustSec advisory database PR adding patched = ["^0.0.13"] is pending review at rustsec/advisory-db#2915. Until it merges, cargo audit may still warn against 0.0.13 — the 0.0.13 release itself ships .cargo/audit.toml + deny.toml ignore entries so the self-referential warning doesn't block your own CI.
Three crates are realistic destinations. Pick the one that fits.
| Crate | Migration shape | Best fit |
|---|---|---|
noyalib |
Drop-in via features = ["compat-serde-yaml"] |
Codebases that want a serde_yml-shaped API on a modern, safe, pure-Rust backend with zero call-site changes |
serde-saphyr |
Path rename for typed code; no Value DOM |
Typed-deserialise workloads (from_str::<MyStruct>) — the 95 % case |
yaml-rust2 |
Lower-level parser API, not serde-integrated | Users who were on serde_yml::libyml / loader (removed in this shim) |
Full per-destination mapping tables: MIGRATION.md.
The shim itself is backed by noyalib internally — that's an implementation detail, not a recommendation. Pick whichever alternative suits your codebase.
The deep internal modules that previous versions exposed leaked implementation details of the C-FFI parser. They are gone in this release:
| Removed | Replacement |
|---|---|
serde_yml::libyml::* (FFI bindings) |
yaml-rust2 for low-level parsing; otherwise n/a |
serde_yml::loader::Loader |
yaml-rust2::YamlLoader or noyalib::load_all_as::<T> |
serde_yml::de::{Event, Progress, DocumentAnchor} |
Covered by the alternatives' streaming APIs |
serde_yml::ser::{SerializerConfig, State} |
noyalib::ser::Config |
serde_yml::modules::path::Path |
Error::location() / Error::path() on any alternative |
serde_yml::value::Index |
Value types in the alternatives implement Index<&str> / Index<usize> natively |
Code calling only the public top-level surface (from_str / to_string / Value / Mapping / with::singleton_map*) needs no changes.
Two intentionally safer defaults flow through the shim:
Value::Tagged rather than being coerced to the inner string. Code exhaustively matching the previous six-variant Value enum needs either a Value::Tagged(_) arm or a call to Value::untag() / Value::untag_ref() before the match.country: NO stays "NO" (the YAML 1.2 fix to the "Norway problem") instead of becoming false.0.0.13 requires Rust 1.85.0 (the backend's MSRV); the previous releases required 1.56. Users who cannot move past 1.56 should pin serde_yml = "=0.0.12" and plan a migration window — but note that pinning 0.0.12 keeps RUSTSEC-2025-0068 in your audit feed.
The runtime dependency tree dropped from six crates to two:
serde_yml v0.0.13
├── noyalib v0.0.5
│ ├── indexmap, memchr, rustc-hash, serde, smallvec
└── serde v1.0.x
No libyml, no unsafe-libyaml, no serde_yaml 0.9. Downstream cargo audit / cargo deny runs stop flagging the unmaintained chain.
README.md — overview, install, behavioural notesMIGRATION.md — full per-destination mapping tables, removed-surface table, test/example coverage triageSECURITY.md — RUSTSEC-2025-0068 status, supported-versions table, reporting policy#[deprecated] banner on every itemDual-licensed under Apache 2.0 or MIT, at your option.
Thanks to everyone who used and contributed to serde_yml. The crate served its purpose; it's time to move on to maintained, safer alternatives.
One column per month.
Serde YML (a fork of Serde YAML)
Serde YML is a Rust library for using the Serde serialization framework with data in YAML file format.
Merge pull request #11 from sebastienrousseau/feat/serde_yml
Full Changelog: v0.0.11...v0.0.12
Serde YML (a fork of Serde YAML)
A Rust library for using the Serde serialization framework with data in YAML file format. This project, has been renamed to Serde YML to avoid confusion with the original Serde YAML crate which is now archived and no longer maintained.
A very small release with a few minor improvements and bug fixes mostly focussed on the latest LibYML v0.0.4 update.
keyword_idents group priorityLicensed under either of Apache License, Version 2.0 or MIT license at your option.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this crate by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
Full Changelog: v0.0.10...v0.0.11
Serde YML (a fork of Serde YAML)
A Rust library for using the Serde serialization framework with data in YAML file format. This project, has been renamed to Serde YML to avoid confusion with the original Serde YAML crate which is now archived and no longer maintained.
This library is a continuation of the excellent work done by David Tolnay and the maintainers of the serde-yaml library.
While Serde YML started as a fork of serde-yaml, it has now evolved into a separate library with its own goals and direction in mind and does not intend to replace the original serde-yaml crate.
If you are currently using serde-yaml in your projects, we recommend carefully evaluating your requirements and considering the stability and maturity of the original library as well as looking at the features and improvements offered by other YAML libraries in the Rust ecosystem.
Licensed under either of Apache License, Version 2.0 or MIT license at your option.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this crate by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
parser.rsutil.rspath.rssafe_cstr.rstag.rsde.rsindex.rsemitter.rsmatch Statements: Fixed an issue where match was used for destructuring a single pattern.error.rs: Ongoing refactoring to improve the code structure and readability.libyml to maintain compatibility and leverage the latest features.Full Changelog: v0.0.9...v0.0.10
Serde YML (a fork of Serde YAML)
A Rust library for using the Serde serialization framework with data in YAML file format. This project, has been renamed to Serde YML to avoid confusion with the original Serde YAML crate which is now archived and no longer maintained.
This library is a continuation of the excellent work done by David Tolnay and the maintainers of the serde-yaml library.
While Serde YML started as a fork of serde-yaml, it has now evolved into a separate library with its own goals and direction in mind and does not intend to replace the original serde-yaml crate.
If you are currently using serde-yaml in your projects, we recommend carefully evaluating your requirements and considering the stability and maturity of the original library as well as looking at the features and improvements offered by other YAML libraries in the Rust ecosystem.
Licensed under either of Apache License, Version 2.0 or MIT license at your option.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this crate by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
lib.rs and safe_cstr.rs.directory.rs.f{32, 64}::consts::PI.value tests.macro_partialeq_numeric.ser.rs.Tag and TagFormatError types.Mapping struct in mapping.rs.macro_from_number.rs.macro_get_field.macro_replace_placeholder.Full Changelog: 0.0.8...v0.0.9
Serde YML (a fork of Serde YAML)
A Rust library for using the Serde serialization framework with data in YAML file format. This project, has been renamed to Serde YML to avoid confusion with the original Serde YAML crate which is now archived and no longer maintained.
This library is a continuation of the excellent work done by David Tolnay and the maintainers of the serde-yaml library.
While Serde YML started as a fork of serde-yaml, it has now evolved into a separate library with its own goals and direction in mind and does not intend to replace the original serde-yaml crate.
If you are currently using serde-yaml in your projects, we recommend carefully evaluating your requirements and considering the stability and maturity of the original library as well as looking at the features and improvements offered by other YAML libraries in the Rust ecosystem.
Licensed under either of Apache License, Version 2.0 or MIT license at your option.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in this crate by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
Serde YML to avoid confusion with the original Serde YAML crate which is now archived and no longer maintained. While Serde YML started as a fork of serde-yaml, it has now evolved into a separate library with its own goals and direction in mind and does not intend to replace the original serde-yaml crate.ci(serde-yaml): :green_heart: add missing release workflow and minor tweaks in READMEtest(serde-yaml): Enhanced test coverage by adding new unit tests for mapping.rs. These tests ensure the robustness and reliability of the Mapping struct and its associated methods.
test(serde-yaml): :white_check_mark: add new tests for mapping.rs``test(serde-yaml): Expanded the test suite by adding comprehensive unit tests for the ser.rs module. The new tests cover various serialization scenarios, including scalar values, sequences, maps, nested structures, optional fields, and custom serializers.
test(serde-yaml): :white_check_mark: add unit tests for the ser.rs moduleNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →