bee
bee copied to clipboard
Tracking Issue for `chrono`/`time` fixes
This is a tracking issue for addressing #783 and #779.
Steps
- [ ] Remove
chronoas a direct dependency of Bee. - [ ] Update any dependencies that have subdependencies on
chronoor an effectedtimeversion, if these have been patched with fixes. - [x] For dependencies that appear inactive, fork and patch them ourselves, and submit a PR to the maintainer.
- [ ] Remove the advisories CI bypass
tracing has merged a patch for this issue, but we are waiting on a release.
Opened this PR for jsonwebtoken, now that simple_asn1 has had a new release, and tokio-console has merged dependency updates.
Looks like a lot has been made regarding to the two security issues, but this tracking issue is not updated for a while.
We're just waiting for dependencies to merge the PRs we did to fix these issues.