Skip to content

Commit 672db86

Browse files
authored
fix: update rand to 0.9.3 for dependabot alert #8 (#336)
Dependabot alert `#8` tracks `GHSA-cq8v-f236-94qc` for `rand`. In this workspace, the runtime `rand 0.9.x` path comes from `secp256k1` and `twox-hash`, and both accept the patched `0.9.3` release. This change updates that vulnerable runtime path with the smallest possible dependency change. [The alert](https://github.com/NomicFoundation/solx/security/dependabot/8) is low-priority and not critical for this repo. Can be merged after the cargo cooldown.
1 parent 6fc0aaf commit 672db86

1 file changed

Lines changed: 8 additions & 8 deletions

File tree

Cargo.lock

Lines changed: 8 additions & 8 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)