-
Notifications
You must be signed in to change notification settings - Fork 277
Open
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Description
https://github.com/RustAudio/rodio/security/dependabot/2
Impact on rodio: low
Our default is symphonia which has no such vulnerabilities.
Possible resolutions
- remove minimp3, symphonia covers all use-cases. The only reason to keep minimp3 is licensing
- fix minimp3 by removing its dependency on slice-ring-buffer. Note I have an old fork of minimp3 which implements seeking. Might be worth fixing it there and then adding seeking support to minimp3 in rodio: https://github.com/dvdsk/minimp3-rs
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file