-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SYS-3868 Update vulnerable cargo.lock dependencies #348
Conversation
…ain into nahu-sys3868-cargolock
Can you list the packages that were identified? |
@thadouk the list is in the Jira ticket and the fix updates related libraries of the ones that we patched to a common "good" version. |
Proposed changes
This PR updates vulnerable dependencies found by running
cargo audit
. There are 5 dependencies identified as vulnerable but unfortunately these require changes to the substrate library to update. Once the substrate upgrade is complete, we can revisit them.Type of change/Merge
🚨What type of change is this PR?
Put an
x
in the boxes that applyChecklist
Put an
x
in the boxes that apply. You can also fill these out after creating the PR.Further comments