-
Notifications
You must be signed in to change notification settings - Fork 224
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Security issues with hyper versions < 0.14.10
#262
Comments
It is hard to upgrade Does As for RUSTSEC-2021-0079 and RUSTSEC-2021-0078 specifically, I'm not sure those specific headers apply to Websockets. |
I See... Yeah we're thinking about switching to |
In my case, I need |
Hi there! I am using the
websocket
crate in one of my projects and I got a hint that I am depending on hyper version 0.10.6, which is vulnerable to RUSTSEC-2021-0079 and RUSTSEC-2021-0078. As it turns out the dependency was introduced through this library. I've looked into this and a potential fix would be to bump the hyper version to>=0.14.10
, but this would introduce quite a few changes to this library as hyper changed it's whole header API (and more).The text was updated successfully, but these errors were encountered: