Skip to content

Conversation

@pietroalbini
Copy link
Member

This PR bumps the version of the git2 and libgit2-sys crates to pull in fixes for GHSA-m4ch-rfv5-x5g3.

This does not fix any security vulnerability: Cargo is already protected thanks to the fixes we implemented as part of CVE-2022-46176. The only purpose of this PR is to avoid dependency scanners from flagging vulnerabilities.

@rustbot
Copy link
Collaborator

rustbot commented Jan 20, 2023

r? @Mark-Simulacrum

(rustbot has picked a reviewer for you, use r? to override)

@rustbot
Copy link
Collaborator

rustbot commented Jan 20, 2023

⚠️ Warning ⚠️

  • Pull requests are usually filed against the master branch for this repo, but this one is against beta. Please double check that you specified the right target!

@rustbot rustbot added the S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. label Jan 20, 2023
@Mark-Simulacrum
Copy link
Member

Closing in favor of #107164.

@pietroalbini pietroalbini deleted the pa-bump-git2-beta branch May 9, 2025 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

S-waiting-on-review Status: Awaiting review from the assignee but also interested parties.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants