From 1a1acfae2c42327dcb0cf67d18f82798346f6de6 Mon Sep 17 00:00:00 2001 From: infrandomness Date: Wed, 26 Jan 2022 22:08:38 +0100 Subject: [PATCH] Fix RUSTSEC-2022-0006 --- CHANGELOG.md | 1 + Cargo.lock | 8 ++++---- common/Cargo.toml | 2 +- common/frontend/Cargo.toml | 2 +- network/Cargo.toml | 2 +- world/Cargo.toml | 2 +- 6 files changed, 9 insertions(+), 8 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9c36389662..e7ce8e0fd8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -73,6 +73,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Made loot boxes drop items instead of doing nothing in order to loot forcing - Refactored agent code file structure - Changed the way light strength is rendered by moving processing from shader code (GPU) to CPU code +- Bumped tracing-subscriber to resolve [RUSTSEC-2022-0006](https://rustsec.org/advisories/RUSTSEC-2022-0006) ### Removed diff --git a/Cargo.lock b/Cargo.lock index 098459832b..965f0343aa 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -5731,9 +5731,9 @@ dependencies = [ [[package]] name = "thread_local" -version = "1.1.3" +version = "1.1.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8018d24e04c95ac8790716a5987d0fec4f8b27249ffa0f7d33f1369bdfb88cbd" +checksum = "5516c27b78311c50bf42c071425c560ac799b11c30b31f87e3081965fe5e0180" dependencies = [ "once_cell", ] @@ -5927,9 +5927,9 @@ dependencies = [ [[package]] name = "tracing-subscriber" -version = "0.3.2" +version = "0.3.7" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7507ec620f809cdf07cccb5bc57b13069a88031b795efd4079b1c71b66c1613d" +checksum = "5312f325fe3588e277415f5a6cca1f4ccad0f248c4cd5a4bd33032d7286abc22" dependencies = [ "ansi_term 0.12.1", "lazy_static", diff --git a/common/Cargo.toml b/common/Cargo.toml index 842ead084e..ca39dce80f 100644 --- a/common/Cargo.toml +++ b/common/Cargo.toml @@ -87,7 +87,7 @@ specs-idvs = { git = "https://gitlab.com/veloren/specs-idvs.git", rev = "8be2abc criterion = "0.3" #test -tracing-subscriber = { version = "0.3.2", default-features = false, features = ["fmt", "time", "ansi", "smallvec", "env-filter"] } +tracing-subscriber = { version = "0.3.7", default-features = false, features = ["fmt", "time", "ansi", "smallvec", "env-filter"] } petgraph = "0.5.1" [[bench]] diff --git a/common/frontend/Cargo.toml b/common/frontend/Cargo.toml index 1cbc383a23..32e5690f4a 100644 --- a/common/frontend/Cargo.toml +++ b/common/frontend/Cargo.toml @@ -16,7 +16,7 @@ termcolor = "1.1" tracing = { version = "0.1", default-features = false } tracing-appender = "0.2.0" tracing-log = "0.1.1" -tracing-subscriber = { version = "0.3.2", default-features = false, features = ["env-filter", "fmt", "time", "ansi", "smallvec", "tracing-log"]} +tracing-subscriber = { version = "0.3.7", default-features = false, features = ["env-filter", "fmt", "time", "ansi", "smallvec", "tracing-log"]} # Tracy tracing-tracy = { version = "0.8.0", optional = true } diff --git a/network/Cargo.toml b/network/Cargo.toml index 71b6d332f1..fc3bb2f03b 100644 --- a/network/Cargo.toml +++ b/network/Cargo.toml @@ -47,7 +47,7 @@ bytes = "^1" hashbrown = { version = ">=0.9, <0.12" } [dev-dependencies] -tracing-subscriber = { version = "0.3.2", default-features = false, features = ["env-filter", "fmt", "time", "ansi", "smallvec"] } +tracing-subscriber = { version = "0.3.7", default-features = false, features = ["env-filter", "fmt", "time", "ansi", "smallvec"] } tokio = { version = "1.14", default-features = false, features = ["io-std", "fs", "rt-multi-thread"] } futures-util = { version = "0.3.7", default-features = false, features = ["sink", "std"] } clap = { version = "2.33", default-features = false } diff --git a/world/Cargo.toml b/world/Cargo.toml index 22a046a5aa..cdb9407086 100644 --- a/world/Cargo.toml +++ b/world/Cargo.toml @@ -52,7 +52,7 @@ clap = { version = "2.33.3", optional = true } common-frontend = { package = "veloren-common-frontend", path = "../common/frontend" } criterion = "0.3" csv = "1.1.3" -tracing-subscriber = { version = "0.3.2", default-features = false, features = ["fmt", "time", "ansi", "smallvec", "env-filter"] } +tracing-subscriber = { version = "0.3.7", default-features = false, features = ["fmt", "time", "ansi", "smallvec", "env-filter"] } minifb = "0.19.1" rusqlite = { version = "0.24.2", features = ["array", "vtab", "bundled", "trace"] } svg_fmt = "0.4"