Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update git2 to v0.18 #71

Merged
merged 1 commit into from
Feb 21, 2024
Merged

update git2 to v0.18 #71

merged 1 commit into from
Feb 21, 2024

Conversation

decathorpe
Copy link
Contributor

Version 0.14 of the git2 crate pulls in libgit2 1.4.5, which was released two years ago, and the 1.4 branch has been out of support for almost that long.

There have been multiple security issues with libgit2 in recent years, most recently, two medium/high severity CVE issues that were only fixed on the 1.7 and 1.6 branches of libgit2. However, only the v0.18 branch of the git2 crate was updated for the latest security fixes, so v0.18 is the only version of the git2 crate that is not vulnerable to any currently known security issues.

Copy link
Owner

@TomasTomecek TomasTomecek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@TomasTomecek TomasTomecek merged commit 3771571 into TomasTomecek:master Feb 21, 2024
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants