Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: update curve library #6381

Merged
merged 1 commit into from
Jun 27, 2024

Conversation

AaronFeickert
Copy link
Collaborator

Description

Updates the curve library dependency.

Motivation and Context

The curve library has a timing vulnerability that was recently fixed. This PR updates the main lock file to pull in the patched version.

How Has This Been Tested?

Existing tests pass.

What process can a PR reviewer use to test or verify this change?

Confirm that the updated version is consistent with the security advisory.

@AaronFeickert
Copy link
Collaborator Author

Note that #6373 is also needed to fully patch this.

@ghpbot-tari-project ghpbot-tari-project added P-acks_required Process - Requires more ACKs or utACKs P-reviews_required Process - Requires a review from a lead maintainer to be merged labels Jun 26, 2024
Copy link

Test Results (Integration tests)

 2 files  11 suites   15m 57s ⏱️
35 tests 34 ✅ 0 💤 1 ❌
37 runs  34 ✅ 0 💤 3 ❌

For more details on these failures, see this check.

Results for commit b59a4ba.

Copy link

Test Results (CI)

    3 files    120 suites   41m 51s ⏱️
1 294 tests 1 294 ✅ 0 💤 0 ❌
3 874 runs  3 874 ✅ 0 💤 0 ❌

Results for commit b59a4ba.

@SWvheerden SWvheerden merged commit 498816d into tari-project:development Jun 27, 2024
14 of 16 checks passed
@AaronFeickert AaronFeickert deleted the curve-update branch June 27, 2024 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
P-acks_required Process - Requires more ACKs or utACKs P-reviews_required Process - Requires a review from a lead maintainer to be merged
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants