From 9079010767d974e050868ebf63176f6dc36c44d1 Mon Sep 17 00:00:00 2001 From: Thomas Eizinger Date: Tue, 8 Feb 2022 01:18:27 +1100 Subject: [PATCH] Update RUSTSEC-2022-0009.md (#1186) * Update RUSTSEC-2022-0009.md We published a semver compatible upgrade that includes the security fix. * A 0.30.x point release has been issued; include it Co-authored-by: Sergey "Shnatsel" Davidoff --- crates/libp2p-core/RUSTSEC-2022-0009.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crates/libp2p-core/RUSTSEC-2022-0009.md b/crates/libp2p-core/RUSTSEC-2022-0009.md index a945a83..279a679 100644 --- a/crates/libp2p-core/RUSTSEC-2022-0009.md +++ b/crates/libp2p-core/RUSTSEC-2022-0009.md @@ -10,7 +10,7 @@ functions = { "libp2p_core::PeerRecord::from_signed_envelope" = [">= 0.30.0-rc.1 [versions] unaffected = ["< 0.30.0-rc.1"] -patched = [">= 0.31.1"] +patched = ["^ 0.30.2", ">= 0.31.1"] ``` # Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord`