-
-
Notifications
You must be signed in to change notification settings - Fork 91
Closed
Labels
securitySecurity relatedSecurity related
Description
I'm wondering if moka is vulnerable to GHSA-qc84-gqf4-9926 (crossbeam-rs/crossbeam#781)
Dependency tree:
moka v0.8.6
├── crossbeam-epoch v0.8.2
│ ├── crossbeam-utils v0.7.2
I could also see that staying with the v0.8.2 is a conscious decision: https://github.com/moka-rs/moka/blob/master/Cargo.toml#L68-L71
In that case, we would need a fix for #34 first.
Metadata
Metadata
Assignees
Labels
securitySecurity relatedSecurity related