Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Remove security issue from openssl<0.10.60 #127

Merged
merged 1 commit into from
Dec 7, 2023

Conversation

assambar
Copy link
Contributor

@assambar assambar commented Dec 7, 2023

Also, update all dependencies to latest versions.

The security fix is to remove openssl dependency in favor of rust-tls. It's propagated through several packages and none of them had the necessary update to >= 0.10.60.

Instead of posting update PRs for all on the dependency chain, I decided to cut it.

fixes https://github.com/vmware-labs/webassembly-language-runtimes/security/dependabot/13

@assambar assambar merged commit 7cd2f8b into main Dec 7, 2023
34 checks passed
@assambar assambar deleted the fix-security-dependabot-13 branch December 7, 2023 08:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants