Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump regex crate version to 1.5.5 because of CVE-2022-24713. #76

Merged
merged 1 commit into from
Jun 7, 2022

Conversation

Peefy
Copy link
Contributor

@Peefy Peefy commented Jun 7, 2022

1. Does this PR affect any open issues?(Y/N) and add issue references (e.g. "fix #123", "re #123".):

  • N
  • Y

https://github.com/KusionStack/KCLVM/security/dependabot/8

2. What is the scope of this PR (e.g. component or file name):

src/runtime/cargo.toml

3. Provide a description of the PR(e.g. more details, effects, motivations or doc link):

  • Affects user behaviors
  • Contains syntax changes
  • Contains variable changes
  • Contains experimental features
  • Performance regression: Consumes more CPU
  • Performance regression: Consumes more Memory
  • Other

4. Are there any breaking changes?(Y/N) and describe the breaking changes(e.g. more details, motivations or doc link):

  • N
  • Y

5. Are there test cases for these changes?(Y/N) select and add more details, references or doc links:

  • Unit test
  • Integration test
  • Manual test (add detailed scripts or steps below)
  • Other

6. Release note

Please refer to Release Notes Language Style Guide to write a quality release note.

None

@Peefy Peefy added this to the v0.4.3 Release milestone Jun 7, 2022
@Peefy Peefy requested review from chai2010 and zong-zhe June 7, 2022 02:53
Copy link
Contributor

@zong-zhe zong-zhe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Contributor

@chai2010 chai2010 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@chai2010 chai2010 merged commit 9ba7758 into main Jun 7, 2022
@github-actions github-actions bot locked and limited conversation to collaborators Jun 7, 2022
@Peefy Peefy deleted the dev/peefy/bump_regex_version branch June 20, 2022 08:16
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants