Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update diesel to 2.2.3 #669

Merged
merged 2 commits into from
Oct 8, 2024
Merged

Conversation

7flying
Copy link
Contributor

@7flying 7flying commented Aug 27, 2024

This closes a high severity security advisory.

This closes a high severity security advisory.

Signed-off-by: Irene Diez <[email protected]>
@7flying
Copy link
Contributor Author

7flying commented Aug 27, 2024

Copy link
Contributor

@nullr0ute nullr0ute left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, and Fedora is up2date

@nullr0ute nullr0ute merged commit f3b204d into fdo-rs:main Oct 8, 2024
15 of 24 checks passed
@mmartinv
Copy link
Contributor

mmartinv commented Oct 9, 2024

This change broke the CentOS Stream 9 builds as diesel 2.2 requires rust 1.78 (vs 1.75 present in CentOS stream 9)

@runcom
Copy link
Contributor

runcom commented Oct 9, 2024

@mmartinv can you revert this while we figure out how to update the toolchain in centos (if we can)

@nullr0ute
Copy link
Contributor

are you sure it's not being bumped for the next el9 release? Do we ship vulverable stacks while awaiting catch up? I don't think this should be reverted

@runcom
Copy link
Contributor

runcom commented Oct 9, 2024

I don't understand, but anyway, this was open since august and as it merged centos broke so what's the difference in reverting for a day while we figure out stuff

@mmartinv
Copy link
Contributor

mmartinv commented Oct 9, 2024

It looks like CentOS Stream 9 is going to ship rust 1.79, not sure how soon though

@nullr0ute
Copy link
Contributor

nullr0ute commented Oct 9, 2024

I don't understand, but anyway, this was open since august and as it merged centos broke so what's the difference in reverting for a day while we figure out stuff

I was looking to cut 0.5.1 to put into Fedora for fixes there as it needs the newer diesel as the older one has been dropped due to the CVEs.

@nullr0ute
Copy link
Contributor

It looks like CentOS Stream 9 is going to ship rust 1.79, not sure how soon though

Looks like c10s is going to that rev too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants