Update versions and revert cortextool #231
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
In the time since the last release, vulnerabilities have been found in downstream
dependencies.
This PR aims to improve matters: it updates various dependencies. More importantly
though: it removes direct inclusion of
cortextool
. This dependency is difficult:it brings a huge number of unfamiliar dependencies which are hard to assess correctly.
It makes much more sense for these to be loosely coupled and responsibility for those
vulns to be handled directly by the authors of cortextool.
Grizzly can still interact with Cortex and Mimir. However, you will now need to have
cortextool
on your command line path for it to work.