Closed felixfaisal closed 2 years ago
Currently, sc-authority-discovery makes use of libp2pv0.40 which has a dependency for lruv0.6.6 which has security issue. Refer to Bug Report
sc-authority-discovery
libp2pv0.40
lruv0.6.6
Recommendation Update dependency libp2p to version 0.41.0 or higher
libp2p
0.41.0
Cargo audit output
Crate: lru Version: 0.6.6 Title: Use after free in lru crate Date: 2021-12-21 ID: RUSTSEC-2021-0130 URL: https://rustsec.org/advisories/RUSTSEC-2021-0130 Solution: Upgrade to >=0.7.1 Dependency tree: lru 0.6.6
@kpp could you do this? Aka upgrading the libp2p version?
Yes
Currently,
sc-authority-discovery
makes use oflibp2pv0.40
which has a dependency forlruv0.6.6
which has security issue. Refer to Bug ReportRecommendation Update dependency
libp2p
to version0.41.0
or higherCargo audit output