Skip to content

Silence RUSTSEC-2024-0421#7308

Merged
MarkusPettersson98 merged 1 commit intomainfrom
silence-rustsec-2024-0421
Dec 10, 2024
Merged

Silence RUSTSEC-2024-0421#7308
MarkusPettersson98 merged 1 commit intomainfrom
silence-rustsec-2024-0421

Conversation

@MarkusPettersson98
Copy link
Copy Markdown
Contributor

@MarkusPettersson98 MarkusPettersson98 commented Dec 9, 2024

This PR silence RUSTSEC-2024-0421 in cargo-deny and osv-scanner. AFAICT, we are not affected by this vulnerability as we do not accept domain names as input anywhere in the app.

Currently we are blocked on getting rid of this vulnerability because of some dependencies of ours needing to cut new releases, most notably hickory-proto and shadowsocks-rs. This is referenced in the comments in the osv-scanner.toml files.


This change is Reviewable

Copy link
Copy Markdown
Collaborator

@pinkisemils pinkisemils left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 4 of 4 files at r1, all commit messages.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved

Copy link
Copy Markdown
Member

@faern faern left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 4 of 4 files at r1, all commit messages.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved

@MarkusPettersson98 MarkusPettersson98 merged commit 1cb6189 into main Dec 10, 2024
@MarkusPettersson98 MarkusPettersson98 deleted the silence-rustsec-2024-0421 branch December 10, 2024 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants