-
-
Notifications
You must be signed in to change notification settings - Fork 119
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RUSTSEC-2020-0146 update cookie
#171
Comments
Thanks! |
Just making sure you got this correct. The crate |
No, that's not how Cargo dependencies work. |
Yes sorry, you are right. Thanks for the update and very quick response. The pipelines work again 👍 |
There was a vulnerability found in
generic-array
.The effected version is still part of the dependency tree of
rocket_http v0.4.7
and thus all part of Rocket.This has been recently added to RustSec advisory database and has thus triggered by automated tools.
You can find more info here:
https://rustsec.org/advisories/RUSTSEC-2020-0146
fizyk20/generic-array#98
It would be advised to create a new minor release where
cookie
is updated to a later version. I see @SergioBenitez recently updatecookie
to a new version so it is already fixed in there. I hope this does not trigger (to many) breaking changes.The text was updated successfully, but these errors were encountered: