Releases: libp2p/rust-libp2p
v0.40.0
See individual changelogs for details.
This is a large release consisting of many small changes. As always, please raise any questions you might have here on this GitHub repository. In addition, feel free to tag @mxinden on the pull request updating your project to v0.40.0
for review.
v0.39.1
See individual changelogs for details.
v0.38.0
See individual changelogs for details.
v0.37.1
See individual changelogs for details.
v0.36.0
See individual changelogs for details.
Version 0.30.0 [2020-11-09]
Among other changes, this release adds a requirement across all crates for multihash
>= v0.11.3
. Rust-libp2p versions in combination with multihash
< v0.11.3
are vulnerable to DoS attacks. Given that e.g. PeerId::from_bytes
is called with unsanitized data from possibly untrusted sources this call can panic with multihash
< v0.11.3
see RustSec for details.
In case you run libp2p
in untrusted environments please either (a) update to libp2p
v0.30.0
or (b) make sure to run with multihash
>=v0.11.3
via your downstream Cargo.lock
file.
As always all other contained changes are listed in our CHANGELOG.md
.