Skip to content

v0.3.1

Latest

Choose a tag to compare

@velikodniy velikodniy released this 09 Jul 16:51
1820c93

Security patch

Updates the transitive bytes dependency to 1.12.1, addressing GHSA-434x-w66g-qw3r — a medium-severity integer overflow in BytesMut::reserve (affected: bytes >= 1.2.1, < 1.11.1). It reaches this crate transitively through ureq, so it applies with the http feature enabled and to the Python wheel (which enables it).

No API changes.

Also

  • Dropped "Official" from the crate/module docs, CLI --help, and the PyPI description, and added a Disclaimer section clarifying the project is not affiliated with, endorsed by, or maintained by HMRC — only the rate data comes from them.