-
Notifications
You must be signed in to change notification settings - Fork 81
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
stellar-ledger crate depends on slip10 crate that depends on dependencies with security advisories #1706
Comments
Until this issue is addressed I'm marking the |
https://crates.io/crates/hd-wallet Alternative crate. Slip10 looks abandoned |
This issue is stale because it has been assigned for 30 days with no activity. It will be closed in 90 days unless the stale label is removed, and the assignee is removed or updated. |
Did this already get fixed? I haen't seen the warning anymore. |
We can close the issue, current version of
|
What version are you using?
8163f30
What did you do?
What did you expect to see?
Swish success.
What did you see instead?
That the version of
curve25519-dalek
anded25519-dalek
required by thestellar-ledger
crate, via theslip10
crate, have known security issues.Discussion
The stellar-cli does not currently use the
stellar-ledger
crate, and to this date we have not actually published the crate either. Before it is used, we should address these advisories.cc @janewang @fnando @elizabethengelman @willemneal
The text was updated successfully, but these errors were encountered: