Conversation
The current version of curl has a couple of CVEs reported against it: CVE-2024-8096 CVE-2024-7264 so update it to a fixed version.
|
Thanks for the pull request, and welcome! The Rust team is excited to review your changes, and you should hear from @Mark-Simulacrum (or someone else) some time within the next two weeks. Please see the contribution instructions for more information. Namely, in order to ensure the minimum review times lag, PR authors and assigned reviewers should ensure that the review label (
|
|
These commits modify the If this was unintentional then you should revert the changes before this PR is merged. |
|
huh, i'm confused by the diff... this should have been updated by #129624? |
|
yeah, it's already updated on master?? Line 843 in a3f76a2 somehow GitHub doesn't want to show that in the diff though, I thought it diffed with current master and not your base? |
|
but yeah, it has already been updated. thank you though! though it would be funny to just merge it anyways |
|
Ah, I guess that must have merged between the time I started and finished my PR. Thanks! I'll just close this off then. |
The current version of curl has a couple of CVEs reported against it:
CVE-2024-8096
CVE-2024-7264
so we should probably update it to a fixed version.