Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-9qxh-258v-666c] owning_ref vulnerable to multiple soundness issues #2853

Conversation

noamtashma
Copy link

Updates

  • Affected products
  • Description

Comments
I've just taken my original fix and pull request for owning_Ref and made it into a crate,
So now people using owning_ref can be directed to that as a possible replacement.

@github-actions github-actions bot changed the base branch from main to noamtashma/advisory-improvement-2853 October 14, 2023 21:00
@CallmeMari
Copy link

Hi @noamtashma, your contribution to GitHub's Advisory Database is much appreciated. Do you have any references that support this change?

@noamtashma
Copy link
Author

@CallmeMari I've punlished it myself, here's the new crate on crates.io
https://crates.io/crates/safer_owning_ref

@darakian
Copy link
Contributor

Hey @noamtashma, sorry but we do not suggest alternatives to vulnerable products as a matter of policy. I'm gonna have to close this out 😞

@darakian darakian closed this Oct 18, 2023
@github-actions github-actions bot deleted the noamtashma-GHSA-9qxh-258v-666c branch October 18, 2023 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants