-
Notifications
You must be signed in to change notification settings - Fork 182
chore: suppress RUSTSEC-2025-0046 #5852
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
WalkthroughIn the shadowed recesses of configuration, the Changes
Estimated code review effort1 (~2 minutes) — A mere whisper in the void, requiring little mortal attention. Suggested reviewers
Beware, for even the smallest configuration may awaken slumbering horrors beneath the surface, where the Elder Gods brood in silence. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Nitpick comments (1)
deny.toml (1)
8-8: Inscribe an expiry rune for this suppressed horrorBy the pallid light of the gibbous moon we cast RUSTSEC-2025-0046 into the abyss, yet even the most potent wards of Yog-Sothoth must one day falter. Etch a dated TODO so future cultists remember to lift the seal once FVM drags in a patched Wasmtime, lest the forgotten menace linger forever.
- "RUSTSEC-2025-0046", # wasmtime issue, this needs to be resolved in FVM + # TODO(✍ 2025-07-??): Remove once ref-fvm depends on a Wasmtime release that exorcises RUSTSEC-2025-0046 + "RUSTSEC-2025-0046", # wasmtime issue, this needs to be resolved in FVM
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
deny.toml(1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (7)
- GitHub Check: cargo-publish-dry-run
- GitHub Check: Build Ubuntu
- GitHub Check: All lint checks
- GitHub Check: Build MacOS
- GitHub Check: Build forest binaries on Linux AMD64
- GitHub Check: tests
- GitHub Check: tests-release
Summary of changes
Changes introduced in this pull request:
Reference issue to close (if applicable)
Closes #5844
Closes #5850
Closes #5847
Closes #5845
Other information and links
Reported in filecoin-project/ref-fvm#2186
Change checklist
Summary by CodeRabbit