-
Notifications
You must be signed in to change notification settings - Fork 14
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Old vulnerable copy of Expat 2.1.0 bundled at ./external/expat/? #18
Comments
Any thoughts? |
@hartwork thanks for checking in on this again. I'm consulting with the team that builds the underlying C++ XMP Toolkit at Adobe to see if there are any potential compatibility issues and to see if we can share effort on vetting the upgrade. No news to share at the moment, but I'll speak up as soon as I know something. |
@hartwork please see libexpat/libexpat#497. That is blocking my ability to update. |
@scouten great to see this fixed, thanks for your work on this topic! 🎉 🙏 |
@hartwork no worries. Thank you for bringing it to my attention and staying with me on this. New versioned release coming momentarily. |
The new version of expat is included in version 0.1.8, which is now published to crates.io. |
Expected Behaviour
Use of a version of Expat with all known vulnerabilities fixed, i.e. >=2.4.0, ideally 2.4.1
Actual Behaviour
Use of known vulnerable Expat 2.1.0
The text was updated successfully, but these errors were encountered: