Downgrade time dependency to 0.3.5#93
Conversation
tankyleo
commented
Feb 5, 2026
We downgrade to a version unaffected by a stack exhaustion denial of service attack in the time dependency reported in https://github.com/time-rs/time/blob/main/CHANGELOG.md#0347-2026-02-05 We cannot upgrade to 0.3.47 as this requires an MSRV bump. We will follow-up with a drop of the time dependency.
|
👋 I see @tnull was un-assigned. |
|
To reproduce: |
|
As discussed elsewhere, I'm not sure we want to do this. It seems we're not directly affected by the vulnerability, so could simply go for dropping the dependencies soon. Here's a summary generated by Claude:
|