mimblewimble/grin

Rust-yaml dependency must be updated

オープン

#2,175 opened on 2018/12/18

 (4 件のコメント) (0 件のリアクション) (0 人の担当者)Rust (991 件のフォーク)batch import
good first issuetask

Repository metrics

Stars
 (4,876 個のスター)
PR merge metrics
 (PR metrics pending)

説明

Currently we use 0.4.2 (used by serde) and 0.3.5 (used by clap). Cargo audit is unhappy:

$cargo audit
    Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 17 security advisories (from /home/ubuntu/.cargo/advisory-db)
    Scanning Cargo.lock for vulnerabilities (311 crate dependencies)
error: Vulnerable crates found!

ID:      RUSTSEC-2018-0006
Crate:   yaml-rust
Version: 0.3.5
Date:    2018-09-17
URL:     https://github.com/chyh1990/yaml-rust/pull/109
Title:   Uncontrolled recursion leads to abort in deserialization
Solution: upgrade to: >= 0.4.1

error: 1 vulnerability found!

I sent a PR against clap, opening this issue to track the update https://github.com/clap-rs/clap/pull/1396

コントリビューターガイド