Skip to content

build: OPS-40: Update local advisory-db#525

Merged
mergify[bot] merged 2 commits intomasterfrom
nm-bumpalo-vuln
Mar 30, 2020
Merged

build: OPS-40: Update local advisory-db#525
mergify[bot] merged 2 commits intomasterfrom
nm-bumpalo-vuln

Conversation

@nmattia
Copy link
Contributor

@nmattia nmattia commented Mar 30, 2020

This fixes vulnerability RUSTSEC-2020-0006. The fix is to update bumpalo to v3.2.1. I've also updated the advisory to the latest.

1st commit: niv update advisory-db
2nt commit: cargo update -p bumpalo

@nmattia nmattia changed the title OPS-40: Update local advisory-db fix: OPS-40: Update local advisory-db Mar 30, 2020
Fixes the following vulnerability:

ID:       RUSTSEC-2020-0006
Crate:    bumpalo
Version:  3.1.2
Date:     2020-03-24
URL:      https://rustsec.org/advisories/RUSTSEC-2020-0006
Title:    Flaw in `realloc` allows reading unknown memory
Solution:  upgrade to >= 3.2.1
@nmattia nmattia marked this pull request as ready for review March 30, 2020 10:31
@nmattia nmattia requested a review from a team March 30, 2020 10:31
@nmattia nmattia requested a review from a team as a code owner March 30, 2020 10:31
@hansl hansl changed the title fix: OPS-40: Update local advisory-db build: OPS-40: Update local advisory-db Mar 30, 2020
@hansl
Copy link
Contributor

hansl commented Mar 30, 2020

fix is for fixes that should be in the release notes. build is more accurate as this is updating a dependency.

@mergify mergify bot merged commit 0f6c8da into master Mar 30, 2020
@nmattia nmattia deleted the nm-bumpalo-vuln branch March 30, 2020 17:34
dfinity-bot added a commit that referenced this pull request Dec 9, 2020
mergify bot pushed a commit that referenced this pull request Dec 9, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants