schultyy / avm

Installs Ruby and node.js on your machine
11 stars 4 forks source link

Upgrade hyper for security #99

Open tirkarthi opened 6 years ago

tirkarthi commented 6 years ago

Hi,

It seems the project uses a version of hyper that is vulnerable to attacks. Please find the advisory as below :

Advisory : https://github.com/RustSec/advisory-db/blob/master/Advisories.toml#L18 Wiki : https://github.com/hyperium/hyper/wiki/Security-001 Commit : https://github.com/hyperium/hyper/commit/39ef63558bf4649452eb0b7d6053c159fc81b9e6

Please consider adding cargo-audit to the CI to get notified in the future. Feel free to close this issue if it has been fixed or irrelevant since this was filed with the help of data from crates.io .

Thanks