Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update rocket_ws dep to pick up security fix. #2823

Closed
wants to merge 1 commit into from
Closed

Conversation

hcldan
Copy link

@hcldan hcldan commented Jul 10, 2024

This may not be needed...
This is the CVE that was reported in our code scans: https://nvd.nist.gov/vuln/detail/CVE-2023-43669

Rocket is already above that version, but our scans are still complaining.
I'm investigating, but will leave this open in case you just want to bump your deps.

@hcldan
Copy link
Author

hcldan commented Jul 10, 2024

It may be because the change log didn't mention it being fixed until 0.23.0
snapview/tungstenite-rs@8b3ecd3

@SergioBenitez
Copy link
Member

Rocket is already above that version, but our scans are still complaining.

Do you know why? We can still update the dep, by the version we're depending on shouldn't be signaling issues.

@hcldan
Copy link
Author

hcldan commented Jul 23, 2024

I have not heard back from our vendor yet. Will ping them again.

@hcldan
Copy link
Author

hcldan commented Jul 25, 2024

Vendor got back to me and determined it was an error in their data.
Will close.

@hcldan hcldan closed this Jul 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants