You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jul 17, 2024. It is now read-only.
Issue description
I keep getting Dependabot alerts for GHSA-2qv5-7mw5-j3cg in my project based on esp32-halv0.16.0. The issue seems to exist in the spin crate for versions below v0.9.8 and using cargo tree I tracked it to this crate which seems to depend on the affected version v0.9.6:
Issue description
I keep getting Dependabot alerts for GHSA-2qv5-7mw5-j3cg in my project based on
esp32-hal
v0.16.0
. The issue seems to exist in thespin
crate for versions belowv0.9.8
and usingcargo tree
I tracked it to this crate which seems to depend on the affected versionv0.9.6
:Potential Solution
Bump the dependency of
spin
to a version that is not vulnerable 🚀The text was updated successfully, but these errors were encountered: