Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bumped cranelift to 0.91.1 following a critical security alert #3670

Merged
merged 3 commits into from
Mar 13, 2023

Conversation

ptitSeb
Copy link
Contributor

@ptitSeb ptitSeb commented Mar 9, 2023

Bumped version of Cranelift to 0.91.1 as the 0.91.0 has a critical security alert on it.

@ptitSeb ptitSeb requested a review from syrusakbary as a code owner March 9, 2023 10:19
@ptitSeb ptitSeb requested a review from theduke March 9, 2023 10:19
@theduke
Copy link
Contributor

theduke commented Mar 9, 2023

@ptitSeb what's the vulnerability?
I can't find anything directly with Google.

@theduke
Copy link
Contributor

theduke commented Mar 9, 2023

Ah, it's GHSA-ff4p-7xrq-q5r8

@ptitSeb
Copy link
Contributor Author

ptitSeb commented Mar 9, 2023

Ah yeah sorry: CVE-2023-26489

@ptitSeb ptitSeb enabled auto-merge (squash) March 9, 2023 10:56
@ptitSeb ptitSeb merged commit 734056e into master Mar 13, 2023
@ptitSeb ptitSeb deleted the upgrade_cranelift_0_91_1 branch March 13, 2023 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants