Skip to content

Unpin and upgrade rand to 0.8.6#129

Closed
danieldickison wants to merge 1 commit intojedisct1:masterfrom
danieldickison:upgrade-rand
Closed

Unpin and upgrade rand to 0.8.6#129
danieldickison wants to merge 1 commit intojedisct1:masterfrom
danieldickison:upgrade-rand

Conversation

@danieldickison
Copy link
Copy Markdown

This addresses RUSTSEC-2026-0097 by allowing rand to be upgraded to a patch version incorporating a fix that was back-ported to 0.8 in rust-random/rand#1772

rand was pinned to =0.8.5 in a4c10d7 a year ago. The 0.8.6 patch was only released last week so I'm guessing the intent of the exact version pinning was to suppress Dependabot trying to upgrade major versions, not to prevent patch upgrades.

@jedisct1
Copy link
Copy Markdown
Owner

The "log" feature is not used, but the dependency has been updated no matter what.
Thanks!

@jedisct1 jedisct1 closed this Apr 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants