Skip to content

Bump rand dependency to version 0.8.6#346

Open
xtqqczze wants to merge 1 commit intoramosbugs:mainfrom
xtqqczze:deps/rand
Open

Bump rand dependency to version 0.8.6#346
xtqqczze wants to merge 1 commit intoramosbugs:mainfrom
xtqqczze:deps/rand

Conversation

@xtqqczze
Copy link
Copy Markdown

Closes #344

@alisterd51
Copy link
Copy Markdown

alisterd51 commented Apr 19, 2026

Hello, this MR seems partially unnecessary, as the Cargo.lock file is only used for OAuth 2 development, and the projects that depend on it only need to run a cargo update to resolve the related CVE.

@xtqqczze
Copy link
Copy Markdown
Author

Whether it is necessary or not, updating avoids any doubt.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RUSTSEC-2026-0097: Rand is unsound with a custom logger using rand::rng()

2 participants