-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Insecure dependencies: chrono/time #1586
Comments
Apparently (some?) |
The versions listed in our It wouldn't hurt to run |
The true problem is that There is a pending PR to deprecate |
In the short term, would be useful to document whether or not (and when) sqlx is using the currently-problematic APIs, maybe? |
It looks like the one place where
It seems that the general advisory would be to stop using
Not for the |
Per https://rustsec.org/advisories/RUSTSEC-2020-0071,
time
versions < 0.2.23 should not be used.The version of
chrono
used (0.4.19) depends on a too-old version oftime
.The text was updated successfully, but these errors were encountered: