Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade rmp-serde to version 1 to pick up fix for RUSTSEC-2022-0092 #4

Closed
wants to merge 1 commit into from

Conversation

johnbatty
Copy link

RustSec advisory: https://rustsec.org/advisories/RUSTSEC-2022-0092.html

This is fixed in rmp-serde 1.1.1: 3Hren/msgpack-rust@5c11a5e

@DoumanAsh
Copy link
Owner

I don't think it affects this crate, but it is fine to bump it
I noticed there is one more outdated dev dependency so instead of bothering you I just made commit myself to bump all deps
b142969

@DoumanAsh DoumanAsh closed this Apr 18, 2023
@DoumanAsh
Copy link
Owner

On side note, it is generally better to bump to minimal version that fixes these RUSTSEC issues as most tools are annoyed even if you bump to required major version.

Version 0.3.3 is released with bumped rmp version

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants