[bug] Tauri 2.1.1 & 1.8.1 is affected by glib-rs 0.15 security vulnerability #12048
Labels
dependencies
Pull requests that update a dependency file
platform: Linux
status: upstream
This issue is blocked by upstream dependencies and we need to wait or contribute upstream fixes
Describe the bug
The
tauri
1.8.1 Rust package currently requires [email protected] on Linux, but versions of glib (the Rust bindings) >=0.15 and <0.20 are affected by GHSA-wrw7-89jp-8q8g . I believe (but am not sure) that the nightly version of Tauri 1 probably depends on [email protected], which is also bad.GitHub informed me about this in https://github.com/ilyagr/diffedit3/security/dependabot/10.
Reproduction
No response
Expected behavior
It'd be great if there was a tauri 1.18.2 that could work with glib 0.20 :)
Full
tauri info
outputStack trace
No response
Additional context
No response
The text was updated successfully, but these errors were encountered: