softprops / hyperlocal

🔌 ✨rustlang hyper bindings for local unix domain sockets
MIT License
227 stars 46 forks source link

Vulnerability GHSA-q6cp-qfwq-4gcv in hyperlocal's dependency - h2 #69

Closed orcame closed 1 week ago

orcame commented 3 months ago

Summary

The dependency h2(0.3.24) has vulnerability issue, check details from https://github.com/advisories/GHSA-q6cp-qfwq-4gcv

Details

The dependency h2(0.3.24) has vulnerability issue, check details from https://github.com/advisories/GHSA-q6cp-qfwq-4gcv Fixed in 0.4.4

The hyper has new version fixed this. Need to update.

Dependency Tree

├─┬ hyperlocal 0.8.0 - Cargo │ └─┬ hyper 0.14.28 - Cargo │ └── h2 0.3.24 - Cargo

softprops commented 1 week ago

we now depend on hyper@1.1