Skip to content

Conversation

@niklaskorz
Copy link

tokio-tar is abandoned and has a high severity CVE that is addressed by astral-tokio-tar 0.5.6

astral-tokio-tar can be used as an actively maintained drop-in replacement

@github-actions
Copy link
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@niklaskorz
Copy link
Author

A simple change like this is certainly not subject to copyright protection, so I will not sign the CLA. Feel free to close this and manually migrate to astral-tokio-tar yourselves if this check can't be skipped.

@rubenfiszel
Copy link
Contributor

Thanks a lot @niklaskorz

I understand why not wanting to sign the CLA. I am not a lawyer myself and are not too interested in legalese but just need your confirmation that you understand that while you will keep authorship of that change, you're giving up ownership of the change/code in our codebase to Windmill Labs, Inc.

@niklaskorz
Copy link
Author

I confirm that I'm giving Windmill Labs, Inc. permission to do whatever they want with the changes in this PR, which is the tokio-tar -> astral-tokio-tar dependency change.

@rubenfiszel
Copy link
Contributor

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants