poanetwork / hbbft

An implementation of the paper "Honey Badger of BFT Protocols" in Rust. This is a modular library of consensus.
Other
357 stars 96 forks source link

`failure` dependency CVE-2019-25010 #438

Open elsirion opened 2 years ago

elsirion commented 2 years ago

Hi, dependabot just informed me of HBBFT's failure dependency having a security relevant bug (CVE-2019-25010). We'll probably fix it in fedimint/hbbft at some point, are you guys still interested in upstream contributions or is the project pretty much dead (Iots of outdated dependencies, no activity etc.)?