We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Currently we use 0.4.2 (used by serde) and 0.3.5 (used by clap). Cargo audit is unhappy:
$cargo audit Fetching advisory database from `https://github.com/RustSec/advisory-db.git` Loaded 17 security advisories (from /home/ubuntu/.cargo/advisory-db) Scanning Cargo.lock for vulnerabilities (311 crate dependencies) error: Vulnerable crates found! ID: RUSTSEC-2018-0006 Crate: yaml-rust Version: 0.3.5 Date: 2018-09-17 URL: https://github.com/chyh1990/yaml-rust/pull/109 Title: Uncontrolled recursion leads to abort in deserialization Solution: upgrade to: >= 0.4.1 error: 1 vulnerability found!
I sent a PR against clap, opening this issue to track the update clap-rs/clap#1396
The text was updated successfully, but these errors were encountered:
It has been fixed in clap clap-rs/clap#1415 waiting for a release
Sorry, something went wrong.
Looks like it won't be release clap-rs/clap#1439.
Still outstanding, and looks as if ncurses and pancurses have been added to the audit unhappiness mix.
Looks like there is a 0.3.0 beta-1. So hopefully that should be fixed soon.
No branches or pull requests
Currently we use 0.4.2 (used by serde) and 0.3.5 (used by clap). Cargo audit is unhappy:
I sent a PR against clap, opening this issue to track the update
clap-rs/clap#1396
The text was updated successfully, but these errors were encountered: