Skip to content

Update Thrift dependency to v0.14.0 or higher #844

@tminusplus

Description

@tminusplus

This was posted previously in #781 but I wanted to check in and see if there is potential for an upgrade / new major release version.

Currently tchannel-go uses Thrift v0.9.3 which has several CVEs posted to it, see here for more info. Additionally using the legacy Thrift version means that this dependency can not be imported into mono-repos which have the newer Thrift version as a dependency.

I'm happy to put in the time to upgrade it - I already have a patch to update it to v0.13.0 and can easily move that up to v0.14.0 or v0.15.0. Let me know if this is a path we can start going down.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions