Skip to content

Conversation

@G8XSU
Copy link
Contributor

@G8XSU G8XSU commented Dec 13, 2024

Earlier versions are impacted by CVE-2024-7254. Even though we don't use groups or nested fields and mostly are not impacted directly. We upgrade nonetheless to ensure safe use in case of unknown fields.

Acc. to

3.25.5 is one of the recommended versions.

Prost in rust is not impacted as far as we know: rustsec/advisory-db#2169 (comment)

Earlier versions are impacted by `CVE-2024-7254`. Even though
we don't use groups or nested fields and mostly are not impacted directly.
We upgrade nonetheless to ensure safe use in case on unknown fields.
@G8XSU G8XSU requested review from Copilot and jkczyz December 13, 2024 21:08
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot reviewed 28 out of 29 changed files in this pull request and generated no comments.

Files not reviewed (1)
  • java/app/build.gradle: Language not supported

@G8XSU G8XSU merged commit 37fe9ae into lightningdevkit:main Dec 13, 2024
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants