Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Github and RustSec Advisories on lexical #10910

Closed
2 tasks done
jqnatividad opened this issue Sep 4, 2023 · 3 comments
Closed
2 tasks done

Github and RustSec Advisories on lexical #10910

jqnatividad opened this issue Sep 4, 2023 · 3 comments
Labels
bug Something isn't working rust Related to Rust Polars

Comments

@jqnatividad
Copy link
Contributor

Checks

  • I have checked that this issue has not already been reported.

  • I have confirmed this bug exists on the latest version of Polars.

Reproducible example

lexical is an active dependency

Log output

No response

Issue description

GHSA-c2hm-mjxv-89r4
https://rustsec.org/advisories/RUSTSEC-2023-0055.html

with the lexical maintainer even specifically calling out polars using lexical as one of his accomplishments:
https://github.com/Alexhuszagh

Expected behavior

replace lexical with an alternative crate/approach as detailed in the advisories

Installed versions

master

@jqnatividad jqnatividad added bug Something isn't working rust Related to Rust Polars labels Sep 4, 2023
@orlp
Copy link
Collaborator

orlp commented Sep 4, 2023

Yes, we're already aware of this and in the process of moving away from lexical.

@orlp
Copy link
Collaborator

orlp commented Sep 4, 2023

Relevant PR: #10655.

@stinodego
Copy link
Member

I'll close this as we're working on it and have the dependabot alert to track this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working rust Related to Rust Polars
Projects
None yet
Development

No branches or pull requests

3 participants