edgebitio / enclaver

Open source toolkit created to enable easy adoption of software enclaves
https://edgebit.io/enclaver
Apache License 2.0
124 stars 12 forks source link

Update dependencies to address GHSA-8qv2-5vq6-g2g7 #162

Closed crawford closed 1 year ago

crawford commented 1 year ago

This is the minimal set of changes required to update webpki to version 0.22.1. The version specifier for reqwest was relaxed to allow for easier updates in the future (the original reason for the fully-specified version was unknown). And hyper-proxy was forked to apply some unmerged pull requests upstream. I tried to contact the author but haven't heard back yet. If those changes are incorporated upstream, we should ditch our fork and use upstream again.