Skip to content

Minimp3 has a security vunerability #774

@dvdsk

Description

@dvdsk

https://github.com/RustAudio/rodio/security/dependabot/2

Impact on rodio: low
Our default is symphonia which has no such vulnerabilities.

Possible resolutions

  • remove minimp3, symphonia covers all use-cases. The only reason to keep minimp3 is licensing
  • fix minimp3 by removing its dependency on slice-ring-buffer. Note I have an old fork of minimp3 which implements seeking. Might be worth fixing it there and then adding seeking support to minimp3 in rodio: https://github.com/dvdsk/minimp3-rs

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions