Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracking Issue for chrono/time fixes #786

Open
1 of 4 tasks
Adam-Gleave opened this issue Oct 20, 2021 · 5 comments
Open
1 of 4 tasks

Tracking Issue for chrono/time fixes #786

Adam-Gleave opened this issue Oct 20, 2021 · 5 comments
Labels
c-tracking-issue Category - Tracking issue

Comments

@Adam-Gleave
Copy link
Contributor

Adam-Gleave commented Oct 20, 2021

This is a tracking issue for addressing #783 and #779.

Steps

  • Remove chrono as a direct dependency of Bee.
  • Update any dependencies that have subdependencies on chrono or an effected time version, if these have been patched with fixes.
  • For dependencies that appear inactive, fork and patch them ourselves, and submit a PR to the maintainer.
  • Remove the advisories CI bypass
@Adam-Gleave Adam-Gleave added the c-tracking-issue Category - Tracking issue label Oct 20, 2021
This was referenced Oct 20, 2021
@Adam-Gleave
Copy link
Contributor Author

tracing has merged a patch for this issue, but we are waiting on a release.

@Adam-Gleave
Copy link
Contributor Author

Adam-Gleave commented Oct 20, 2021

Opened this PR for simple_asn1, which is used in jsonwebtoken.

(This has now been merged).

@Adam-Gleave
Copy link
Contributor Author

Opened this PR for jsonwebtoken, now that simple_asn1 has had a new release, and tokio-console has merged dependency updates.

@jyhi
Copy link

jyhi commented Nov 18, 2021

Looks like a lot has been made regarding to the two security issues, but this tracking issue is not updated for a while.

@thibault-martinez
Copy link
Member

We're just waiting for dependencies to merge the PRs we did to fix these issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c-tracking-issue Category - Tracking issue
Projects
None yet
Development

No branches or pull requests

3 participants