rust-av / av-metrics

Quality metrics
MIT License
53 stars 9 forks source link

Update shlex to fix security issue #301

Closed FreezyLemon closed 6 months ago

FreezyLemon commented 6 months ago

https://github.com/rust-av/av-metrics/security/dependabot/9

Not sure if bindgen/ffmpeg-the-third is actually affected by this. The upgrade should still be done out of an abundance of caution

shssoichiro commented 6 months ago

Seems like CI is upset about the ffmpeg crate. I think the other PRs you submitted there should fix this, probably just needs a version bump of that crate, but I'll merge this because of security.