-
-
Notifications
You must be signed in to change notification settings - Fork 15
Security #1: Attempt to bump up generic-array
#22
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security #1: Attempt to bump up generic-array
#22
Conversation
|
The linked report does not exist: 404. |
|
What about now? |
tmplt
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Still can't access the report. But both dep bumps LGTM. I'd rewrite the commit:
cargo: bump nb, cortex-m
nb bumped due to <link to report>.
or similar.
hal/Cargo.toml
Outdated
| [package] | ||
| name = "atsamx7x-hal" | ||
| version = "0.1.0" | ||
| version = "0.2.0" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Techically, a MINOR bump is overkill. A PATCH bump suffices.
|
|
||
| [dependencies] | ||
| cortex-m = "0.7" | ||
| cortex-m = "0.7.5" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Commit does not mention a cortex-m bump.
32bb559 to
a2b53ef
Compare

Addresses report from dependabot: https://github.com/atsams-rs/atsamx7x-rust/security/dependabot/1