Skip to content

Relax upper bound for text-iso8601 to 0.3#161

Open
dancewithheart wants to merge 1 commit into
fizruk:masterfrom
dancewithheart:update-text-iso8601
Open

Relax upper bound for text-iso8601 to 0.3#161
dancewithheart wants to merge 1 commit into
fizruk:masterfrom
dancewithheart:update-text-iso8601

Conversation

@dancewithheart
Copy link
Copy Markdown

Verified with:

cabal build all
cabal test all

With this change cabal-audit no longer reports HSEC-2026-0007:

Hackage package text-iso8601 at version 0.1.1.1 is vulnerable for:
  HSEC-2026-0007 "Denial of Service and Memory Exhaustion in aeson and text-iso8601"
  published: 2026-05-22 07:02:58 UTC
  https://haskell.github.io/security-advisories/advisory/HSEC-2026-0007
  Fix available since version 0.2.0.0
  aeson, text-iso8601, dos, memory-exhaustion, json

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant