Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump generic-array from 0.12.3 to 0.12.4 to fix RUSTSEC-2020-0146 #2601

Merged

Conversation

@yangby-cryptape yangby-cryptape requested review from a team and xxuejie March 3, 2021 02:11
@quake
Copy link
Member

quake commented Mar 3, 2021

bors r=quake,zhangsoledad

@bors
Copy link
Contributor

bors bot commented Mar 3, 2021

🕐 Waiting for PR status (Github check) to be set, probably by CI. Bors will automatically try to run when all required PR statuses are set.

@yangby-cryptape
Copy link
Collaborator Author

yangby-cryptape commented Mar 3, 2021

For RUSTSEC-2020-0146:

  • CKB depends on generic-array=0.14.4, too.
  • But block-buffer=0.7.3 and digest=0.8.0 requires generic-array=0.12.
  • CKB also depends on block-buffer=0.9.0 and digest=0.9.0.
  • But sha-1=0.8.1 requires block-buffer=0.7 and digest=0.8.
  • sha-1=0.9.4 only depends on block-buffer=0.9 and digest=0.9.
  • But ws depends on sha-1=0.8, and ws haven't release new versions for 18 months.

ws also has many other issues (more than 100 issues in it's issues list):

So, maybe we have to upgrade jsonrpc-*.

@bors
Copy link
Contributor

bors bot commented Mar 3, 2021

Build succeeded:

@bors bors bot merged commit 1615497 into nervosnetwork:develop Mar 3, 2021
@yangby-cryptape yangby-cryptape deleted the pr/fix-RUSTSEC-2020-0146 branch March 4, 2021 03:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants