Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update the idna dep (and url, hickory-proto) #1788

Open
wants to merge 3 commits into
base: main
Choose a base branch
from

Conversation

leighmcculloch
Copy link
Member

@leighmcculloch leighmcculloch commented Dec 11, 2024

What

Update the idna dep, and update transitive deps accordingly, as well as the url and hickory-proto deps to be able to use the newer idna.

Why

The idna crate that the url and hickory-proto crate depend on has a rust security alert seen in the cargo-deny runs:

Commands run for anyone wishing to verify / replicate:

$ cargo update -p url
$ cargo update -p hickory-proto

@leighmcculloch leighmcculloch marked this pull request as ready for review December 11, 2024 08:48
@leighmcculloch leighmcculloch enabled auto-merge (squash) December 11, 2024 08:48
@leighmcculloch leighmcculloch changed the title update the url dep from 2.5.2 to 2.5.4 update the idna dep (and url, hickory-proto) Dec 11, 2024
@leighmcculloch
Copy link
Member Author

leighmcculloch commented Dec 11, 2024

Pending question with legal regarding the Unicode-3.0 license error:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Backlog (Not Ready)
Development

Successfully merging this pull request may close these issues.

1 participant