•  
      request #31172 Tempfile: 3.3.0 -> 3.4.0
    Infos
    #31172
    Thomas Piras (tpiras)
    2023-03-20 14:10
    2023-03-20 12:03
    32775
    Details
    Tempfile: 3.3.0 -> 3.4.0

    This library is used by cbindgen, which we use in wasmtime-wrapper-lib. Prior tempfile releases depended on remove_dir_all version 0.5.0 which was vulnerable to a TOCTOU. Upgrading it fixes https://rustsec.org/advisories/RUSTSEC-2023-0018.html.

    https://github.com/Stebalien/tempfile/blob/master/NEWS

    Dev tools
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Piras (tpiras)
    Closed
    2023-03-20
    Attachments
    Empty
    References
    Referencing request #31172
    Referenced by request #31172

    Artifact Tracker v5

    rel #30364 14.7

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2023-03-20 14:10

    Integrated into Tuleap 14.6.99.141.


    • Status changed from New to Closed
    • Connected artifacts
    • Close date set to 2023-03-20