Skip to content

Bump the vulnerable dependencies#1985

Merged
sgkim126 merged 1 commit intoCodeChain-io:rc-2.2.xfrom
majecty:f/dependency
Aug 27, 2020
Merged

Bump the vulnerable dependencies#1985
sgkim126 merged 1 commit intoCodeChain-io:rc-2.2.xfrom
majecty:f/dependency

Conversation

@majecty
Copy link

@majecty majecty commented Aug 26, 2020

All bump up includes minor updates. I checked this using cargo-audit.

Updated dependencies:

  • http 0.1.17 -> 0.1.21
  • hyper 0.12.19 -> 0.12.35
  • smallvec 0.6.4 -> 0.6.13
  • libflate 0.1.23 -> 0.1.27
  • spin 0.5.0 -> 0.5.2
  • yaml-rust: This commit updates clap instead. clap 2.33 does not
    affected by the problem.

Links about the security advisories

@majecty majecty requested a review from sgkim126 August 26, 2020 05:28
All bump up includes minor updates.

Updated dependencies:

* http 0.1.17 -> 0.1.21
* hyper 0.12.19 -> 0.12.35
* smallvec 0.6.4 -> 0.6.13
* libflate 0.1.23 -> 0.1.27
* spin 0.5.0 -> 0.5.2
* yaml-rust: This commit updates clap instead. clap 2.33 does not
affected by the problem.

* https://rustsec.org/advisories/RUSTSEC-2019-0034
* https://rustsec.org/advisories/RUSTSEC-2019-0033
* https://rustsec.org/advisories/RUSTSEC-2020-0008
* https://rustsec.org/advisories/RUSTSEC-2019-0010
* https://rustsec.org/advisories/RUSTSEC-2019-0012
* https://rustsec.org/advisories/RUSTSEC-2019-0013
* https://rustsec.org/advisories/RUSTSEC-2018-0006
@sgkim126 sgkim126 merged commit ce53f3c into CodeChain-io:rc-2.2.x Aug 27, 2020
@majecty majecty deleted the f/dependency branch August 27, 2020 06:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants