Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade byteorder to 1.4 #100

Merged
merged 1 commit into from
May 20, 2021

Conversation

oxarbitrage
Copy link
Contributor

@oxarbitrage oxarbitrage commented May 14, 2021

From the audit "3.2 Outdated dependencies"

The rand_core was updated on April 3rd by #55. This PR updates byteorder.

We should check how we are in all other dependencies, best if we can automate it.

@oxarbitrage oxarbitrage mentioned this pull request May 14, 2021
10 tasks
@mpguerra mpguerra linked an issue May 17, 2021 that may be closed by this pull request
10 tasks
@mpguerra mpguerra removed a link to an issue May 17, 2021
10 tasks
@teor2345
Copy link
Contributor

We should check how we are in all other dependencies, best if we can automate it.

dependabot can automate dependency updates.

@teor2345
Copy link
Contributor

We should check how we are in all other dependencies, best if we can automate it.

dependabot can automate dependency updates.

There are 4 outstanding dependabot PRs, but its open pull request limit is 10:
https://github.com/ZcashFoundation/redjubjub/blob/main/.github/dependabot.yml#L18

So all outstanding dependency bumps are either in an open PR, or they've been closed or merged:
https://github.com/ZcashFoundation/redjubjub/pulls?q=is%3Apr+is%3Aclosed+label%3Adependencies

@oxarbitrage
Copy link
Contributor Author

I don't see byteorder in the list.

@mpguerra mpguerra requested a review from dconnolly May 17, 2021 13:45
@dconnolly dconnolly assigned dconnolly and unassigned dconnolly May 20, 2021
@dconnolly dconnolly added the dependencies Pull requests that update a dependency file label May 20, 2021
@dconnolly dconnolly merged commit 11ccf5d into ZcashFoundation:main May 20, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants