-
Notifications
You must be signed in to change notification settings - Fork 71
Apply dependabot security fixes #214
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
I don't understand these CI failures. Note that they also occur in #212 (the automated version of this PR). |
|
I'm not really sure either, but it sounds like a new manifestation of what is ultimately an MSRV problem. |
|
I think the salient point is so yes, this is a MSRV problem, i.e. we need to lock down certain dependencies, in this |
|
But I think completing the CI overhaul would be time better spent, because as discussed there, I do not see why our MSRV policy should extend to demo/example code at all. Fixing what the CI actually tests first would be preferable IMHO. |
|
I believe that PR just needs a rebase, if people are happy with it. |
|
(#204) |
4c25bc8 to
627532e
Compare
|
Our nalgebra dev dependency indirectly (via However, the
|
I would prefer the exclusion. |
627532e to
018c608
Compare
018c608 to
85625f4
Compare
|
We're now passing, with the following changes:
|
See:
https://github.com/georust/rstar/security/dependabot/3
https://github.com/georust/rstar/security/dependabot/4
https://github.com/georust/rstar/security/dependabot/5
https://github.com/georust/rstar/security/dependabot/6
rstar/CHANGELOG.mdif knowledge of this change could be valuable to users.