Skip to content

Update keccak and rand 0.8.x#28

Open
cr-tk wants to merge 1 commit into
mainfrom
christian/collection-patch1
Open

Update keccak and rand 0.8.x#28
cr-tk wants to merge 1 commit into
mainfrom
christian/collection-patch1

Conversation

@cr-tk

@cr-tk cr-tk commented May 21, 2026

Copy link
Copy Markdown
Contributor

Update the keccak and rand crates due to known issues GHSA-3288-p39f-rqpv and GHSA-cq8v-f236-94qc.

Note that we can not fully fix rand 0.7.3 yet due to transitive dependencies.

@cr-tk

cr-tk commented May 21, 2026

Copy link
Copy Markdown
Contributor Author

Note for dependency security reviewers: we already trust the new rand and keccak versions, see https://github.com/tkhq/qos/blob/main/Cargo.lock.

@cr-tk cr-tk added the bug Something isn't working label May 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant