-
Notifications
You must be signed in to change notification settings - Fork 204
Conversation
I highly recommend you do not rely on |
Versions of time crate prior to 0.2.23 fail audit due to RUSTSEC-2020-0071. Crate: time Version: 0.1.43 Title: Potential segfault in the time crate Date: 2020-11-18 ID: RUSTSEC-2020-0071 URL: https://rustsec.org/advisories/RUSTSEC-2020-0071 Solution: Upgrade to >=0.2.23
e447070
to
2f71810
Compare
@jhpratt thanks for the recommendation, I removed the |
Thanks for the PR! I'm still not sure we need the For those investigating this issue, it appears that the vulnerability doesn't affect Can you please bump the MSRV version to support your clippy annotations, and I'll merge this :) |
No, |
Oh! My mistake, then this needs to be pushed through promptly. Do you know how this should be addressed w.r.t yanking? |
Personally, I decided to leave the affected time versions up, as it would mean yanking the entirety of 0.1 (I wasn't concerned about the early releases of 0.2). For zip, I don't see it as an issue that needs yanking, as it requires some very uncommon circumstances to occur. That is, of course, my opinion. Do what you feel is best. |
831c451
to
0ee34bd
Compare
I bumped MSRV to 1.52.0 which should conform to your MSRV policy of 4 minor releases prior to current stable. Also fixed |
@Plecra can we get this out now? Thanks! |
@Plecra. I too would really like to see this PR released as soon as possible. I know your probably busy, but is there anything we can do to help you with this. |
Versions of time crate prior to 0.2.23 fail audit due to RUSTSEC-2020-0071.
Crate: time
Version: 0.1.43
Title: Potential segfault in the time crate
Date: 2020-11-18
ID: RUSTSEC-2020-0071
URL: https://rustsec.org/advisories/RUSTSEC-2020-0071
Solution: Upgrade to >=0.2.23