-
Notifications
You must be signed in to change notification settings - Fork 39
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(drive): security vulnerability in hashbrown #2375
Conversation
WalkthroughThe pull request modifies the Changes
Possibly related PRs
Suggested reviewers
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
⛔ Files ignored due to path filters (1)
Cargo.lock
is excluded by!**/*.lock
📒 Files selected for processing (1)
packages/rs-drive-abci/Cargo.toml
(1 hunks)
🔇 Additional comments (2)
packages/rs-drive-abci/Cargo.toml (2)
61-63
: Verify if these updates address the hashbrown vulnerability
While the PR aims to fix the hashbrown security vulnerability (RUSTSEC-2024-0402), it's not immediately clear if updating these metrics-related crates effectively addresses the issue. Let's verify the dependency chain and versions.
61-63
: Verify impact on Borsh serialization
Since the vulnerability affects Borsh serialization of HashMaps, we should verify where HashMap serialization is used in the codebase.
Issue being fixed or feature implemented
Rust audit is failing:
What was done?
metrics
andmetrics-exporter-prometheus
cratesHow Has This Been Tested?
With CI
Breaking Changes
None
Checklist:
For repository code-owners and collaborators only
Summary by CodeRabbit
metrics
dependency to enhance performance.metrics-exporter-prometheus
dependency for improved functionality.