Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release 0.9.4 is affected by RUSTSEC-2024-0384 #338

Open
MarkusPettersson98 opened this issue Nov 11, 2024 · 1 comment
Open

Release 0.9.4 is affected by RUSTSEC-2024-0384 #338

MarkusPettersson98 opened this issue Nov 11, 2024 · 1 comment
Labels

Comments

@MarkusPettersson98
Copy link

Hello, thanks for the great crate!

I just want to bring attention to RUSTSEC-2024-0384 - instant is unmaintained. The problem here is that the latest release of ssh2 depend on instant through parking_lot 0.11, but parking_lot 0.12 was merged to main since over a year ago.

Please consider cutting a new release so that projects that check for vulnerabilities reported to the OSV database don't have to silence this warning or change to a git dependency on ssh2 🙏

@yodaldevoid
Copy link
Collaborator

Thank you for bringing this to my attention. I will look at making a release this weekend.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants