Skip to content

Building volta fails - zip < 2.3.0 has been yanked from crates.io. #2028

@MarkusPettersson98

Description

@MarkusPettersson98

Hi 👋

I just want to bring to your attention that one of your dependencies - zip 2.1.6 - has been yanked due to being vulnerable to this CVE: GHSA-94vh-gphv-8pm8. As such, checking out the volta repository and trying to build it will fail.

Thanks for maintaining Volta 💛

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions