Skip to content

feat: update dependencies due to vulnerabilities#9

Open
somehowchris wants to merge 1 commit intoimager-io:masterfrom
somehowchris:master
Open

feat: update dependencies due to vulnerabilities#9
somehowchris wants to merge 1 commit intoimager-io:masterfrom
somehowchris:master

Conversation

@somehowchris
Copy link
Copy Markdown

@somehowchris somehowchris commented Apr 18, 2021

Hey man,

Awesome tool. Tried it out locally and noticed some vulnerabilities and unpinned libraries. For security purposes, I pinned some of them and updated the docker image.

If you plan to keep that thing up to date (which would be awesome) I would recommend to add dependabot or something like it.

There are a f**** ton of lines updated due to cargo fmt. The main changes are the Cargo.toml files, the Dockerfile and the two imports of image::FileType moved to image::imageops::FileType and image::ConvertBuffer moved to image::buffer::ConvertBuffer

Do you plan to publish the docker image yourself?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant