Skip to content

lexical dependency is unsound #4

@ivan770

Description

@ivan770

Hi.

json-number has a dependency on lexical, which contains multiple soundness issues within its implementation. Dependabot mentions that libcore already integrated the updated float parsing algorithm, making it possible to remove the dependency entirely.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions