Skip to content

Vulnerable to CVE-2022-23639? #162

@yanns

Description

@yanns

I'm wondering if moka is vulnerable to GHSA-qc84-gqf4-9926 (crossbeam-rs/crossbeam#781)

Dependency tree:

moka v0.8.6
├── crossbeam-epoch v0.8.2
│   ├── crossbeam-utils v0.7.2

I could also see that staying with the v0.8.2 is a conscious decision: https://github.com/moka-rs/moka/blob/master/Cargo.toml#L68-L71
In that case, we would need a fix for #34 first.

Metadata

Metadata

Assignees

Labels

securitySecurity related

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions