Skip to content

Bump tracing-subscriber and temporarily ignore RUSTSEC-2025-0055 for internal dependencies#1613

Merged
dmitrylavrenov merged 3 commits intomasterfrom
ignore-RUSTSEC-2025-0055
Sep 15, 2025
Merged

Bump tracing-subscriber and temporarily ignore RUSTSEC-2025-0055 for internal dependencies#1613
dmitrylavrenov merged 3 commits intomasterfrom
ignore-RUSTSEC-2025-0055

Conversation

@dmitrylavrenov
Copy link
Contributor

@dmitrylavrenov dmitrylavrenov commented Sep 15, 2025

https://rustsec.org/advisories/RUSTSEC-2025-0055

We have internal substrate fork dependencies that are still depend on vulnerable tracing-subscriber version.

Agreed to ignore it for now until we update substrate version.

The issue has been created - #1612

@dmitrylavrenov dmitrylavrenov changed the title Temporarily ignore RUSTSEC-2025-0055 Bump tracing-subscriber and temporarily ignore RUSTSEC-2025-0055 for internal dependencies Sep 15, 2025
@dmitrylavrenov dmitrylavrenov changed the title Bump tracing-subscriber and temporarily ignore RUSTSEC-2025-0055 for internal dependencies Bump tracing-subscriber and temporarily ignore RUSTSEC-2025-0055 for internal dependencies Sep 15, 2025
@dmitrylavrenov dmitrylavrenov added this pull request to the merge queue Sep 15, 2025
Merged via the queue into master with commit a011dfb Sep 15, 2025
21 checks passed
@dmitrylavrenov dmitrylavrenov deleted the ignore-RUSTSEC-2025-0055 branch September 15, 2025 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants