Skip to content

chore: update deny rules#878

Merged
Ad96el merged 2 commits intodevelopfrom
ag_deny_rule_update
Mar 28, 2025
Merged

chore: update deny rules#878
Ad96el merged 2 commits intodevelopfrom
ag_deny_rule_update

Conversation

@Ad96el
Copy link
Contributor

@Ad96el Ad96el commented Mar 27, 2025

No description provided.

@Ad96el Ad96el marked this pull request as ready for review March 27, 2025 10:01
@Ad96el Ad96el requested a review from rflechtner March 27, 2025 10:01
@Ad96el Ad96el added the ci-skip-docs-pr ci-skip-docs-pr label Mar 27, 2025
{ id = "RUSTSEC-2024-0388", reason = "`derivative` is unmaintained but a Substrate dependency. Re-verify upon next polkadot-sdk updates." },
{ id = "RUSTSEC-2024-0421", reason = "`idna` has a security vulnerability but a Substrate dependency. Re-verify upon next polkadot-sdk updates." },
{ id = "RUSTSEC-2024-0436", reason = "`paste` is unmaintained but a Substrate dependency. Re-verify upon next polkadot-sdk updates." },
{ id = "RUSTSEC-2025-0009", reason = "`ring` has a security vulnerability but a Substrate dependency. Re-verify upon next polkadot-sdk updates." },
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

while there is a 0.16 version of ring in the tree that cannot be updated, there is also a 0.17 version that can, did you do that?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Version 17 has no security issue. What do you exactly mean?

@Ad96el Ad96el merged commit 368399f into develop Mar 28, 2025
17 checks passed
@Ad96el Ad96el deleted the ag_deny_rule_update branch March 28, 2025 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-skip-docs-pr ci-skip-docs-pr

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants