Skip to content

v0.1.4

Latest

Choose a tag to compare

@lichendust lichendust released this 08 Jan 10:42
· 2 commits to main since this release

Updates gorilla/websocket, which drops golang.org/x/net as a dependency, fixing any chance of CVE-2024-45338 affecting Toil's parsing, which it probably didn't.

Note: Never use Toil as a production server. It's not a production server and does not threat model this way. I'm only fixing this because Dependabot wouldn't stop emailing me about it.

go install github.com/lichendust/toil@latest

There are also binaries attached below, but you should prefer to build your own for the latest Go updates and security fixes in the net/http and websocket packages.