-
Notifications
You must be signed in to change notification settings - Fork 34
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: update diesel to 2.2.3 #669
Conversation
This closes a high severity security advisory. Signed-off-by: Irene Diez <[email protected]>
Fedora still hasn't 2.2.3 https://packages.fedoraproject.org/pkgs/rust-diesel/rust-diesel-devel/ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good, and Fedora is up2date
This change broke the CentOS Stream 9 builds as diesel 2.2 requires rust 1.78 (vs 1.75 present in CentOS stream 9) |
@mmartinv can you revert this while we figure out how to update the toolchain in centos (if we can) |
are you sure it's not being bumped for the next el9 release? Do we ship vulverable stacks while awaiting catch up? I don't think this should be reverted |
I don't understand, but anyway, this was open since august and as it merged centos broke so what's the difference in reverting for a day while we figure out stuff |
It looks like CentOS Stream 9 is going to ship rust 1.79, not sure how soon though |
I was looking to cut 0.5.1 to put into Fedora for fixes there as it needs the newer diesel as the older one has been dropped due to the CVEs. |
Looks like c10s is going to that rev too. |
This closes a high severity security advisory.