Skip to content

Revert time pin and/or drop jsonwebtoken dependency ASAP #92

@tnull

Description

@tnull

The time crate just reported a security vulnerability (see rustsec/advisory-db#2626) that was fixed in v0.3.47, one patch release after previously bumping MSRV to rustc v1.88 on v0.3.46.

We're now in a pickle as this probably means we'll have to either revert the pin or drop any dependency depending on time. We currently depend on it through jsonwebtoken and simple_asn1. From a first quick inspection it looks we might not be affected (simple_asn1 only uses PrimitiveDateTime, not the affected Rfc2822, AFAICT), but we should still take action ASAP.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions