jonhoo / inferno

A Rust port of FlameGraph
Other
1.64k stars 117 forks source link

Bump ahash dependency #307

Closed julianbraha closed 9 months ago

julianbraha commented 9 months ago

The currently-used version of ahash, 0.8.3 was yanked due to this vulnerability: tkaitchuck/aHash#163

This PR bumps it to 0.8.6, the latest version.

jonhoo commented 9 months ago

Thanks for the heads up! It shouldn't be necessary to update Cargo.toml, since for binary consumers the latest version (or what's in Cargo.lock) will be used, and for library consumers they should be permitted to control the version they consume through their Cargo.toml/Cargo.lock. I'll push a commit + release that just cargo update -p ahash for binary consumers :+1:

jonhoo commented 9 months ago

Published fix in 0.11.18 :tada: