Comment 18 for bug 1990655

Revision history for this message
Seth Arnold (seth-arnold) wrote :

Zixing has mentioned in 2023-09-12 MIR team meeting that replacing http-parse with llhttp is another possibility: in case the foundations team can't address a security issue in http-parse, they can replace the library in its entirety in cargo. But rather than front-load this work, we hold off on the switch until such time as http-parse is found to be harder to fix than to replace.

Thanks