Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

GHSA-2326-pfpj-vx3h - parsable: pending-upstream-fix advisory#8563

Merged
mamccorm merged 1 commit intowolfi-dev:mainfrom
mamccorm:GHSA-2326-pfpj-vx3h-parsable-package-advisory
Oct 6, 2024
Merged

GHSA-2326-pfpj-vx3h - parsable: pending-upstream-fix advisory#8563
mamccorm merged 1 commit intowolfi-dev:mainfrom
mamccorm:GHSA-2326-pfpj-vx3h-parsable-package-advisory

Conversation

@mamccorm
Copy link
Member

@mamccorm mamccorm commented Oct 5, 2024

Filing a ending-upstream-fix advisory for GHSA-2326-pfpj-vx3h, which relates to the parsable package, and one of it's dependencies: lexical-core.


After this is approved / merged, please close the following PR and delete the associated branch:

…2326-pfpj-vx3h

Signed-off-by: Mark McCormick <mark.mccormick@chainguard.dev>
@mamccorm mamccorm marked this pull request as ready for review October 5, 2024 21:50
@mamccorm mamccorm enabled auto-merge October 5, 2024 21:50
Copy link
Member

@kranurag7 kranurag7 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

there was a release cut of 53.1.0 via apache/arrow-rs#6501

the main workspace version is also 53.1.0 now (https://github.com/apache/arrow-rs/blob/master/Cargo.toml) but I think this has not been updated to crates.io till now which still shows 53.0.0 (https://crates.io/crates/arrow-json)

approving meanwhile given crates.io is not updated for the crate that relates to the GHSA.

@mamccorm mamccorm added this pull request to the merge queue Oct 6, 2024
Merged via the queue into wolfi-dev:main with commit 890a315 Oct 6, 2024
@mamccorm mamccorm deleted the GHSA-2326-pfpj-vx3h-parsable-package-advisory branch October 6, 2024 00:42
@mamccorm mamccorm self-assigned this Oct 16, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants