Commit 173a374
committed
Fix dcap-qvl security vulnerability in key-provider-build
Switch to kvinwang fork with dcap-qvl upgraded from 0.2.0 to 0.3.10.
This fixes "Missing Verification for QE Identity" vulnerability.
- Update Cargo.lock with dcap-qvl 0.3.10
- Verified release build succeeds
Security advisory: GHSA-796p-j2gh-9m2q
Upstream PR: MoeMahhouk/gramine-sealing-key-provider#131 parent 53cf142 commit 173a374
2 files changed
+1133
-591
lines changed
0 commit comments