nix-community / nixpkgs-fmt

Nix code formatter for nixpkgs [maintainer=@zimbatm]
https://nix-community.github.io/nixpkgs-fmt/
Apache License 2.0
581 stars 34 forks source link

Bump cargo deps (CVE-2022-23639) #327

Open dmadisetti opened 5 months ago

dmadisetti commented 5 months ago

I've been getting alerts about security issues in crossbeam for years: https://nvd.nist.gov/vuln/detail/CVE-2022-23639

Can we just bump all the deps?

zimbatm commented 5 months ago

Looking at the CVE, it doesn't seem to be a practical exploit for this project. But be my guest, happy to get PRs.