Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump ahash dependency #307

Closed
wants to merge 1 commit into from
Closed

Bump ahash dependency #307

wants to merge 1 commit into from

Conversation

julianbraha
Copy link

The currently-used version of ahash, 0.8.3 was yanked due to this vulnerability: tkaitchuck/aHash#163

This PR bumps it to 0.8.6, the latest version.

@jonhoo
Copy link
Owner

jonhoo commented Nov 11, 2023

Thanks for the heads up! It shouldn't be necessary to update Cargo.toml, since for binary consumers the latest version (or what's in Cargo.lock) will be used, and for library consumers they should be permitted to control the version they consume through their Cargo.toml/Cargo.lock. I'll push a commit + release that just cargo update -p ahash for binary consumers 👍

@jonhoo jonhoo closed this in 993b100 Nov 11, 2023
@jonhoo
Copy link
Owner

jonhoo commented Nov 11, 2023

Published fix in 0.11.18 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants