Merged
Conversation
c6a6057 to
fdfadc8
Compare
RUSTSEC-2024-0370
SuperFluffy
approved these changes
Sep 20, 2024
Contributor
SuperFluffy
left a comment
There was a problem hiding this comment.
I suppose we should make an issue over at borsh?
Contributor
Author
There's an issue logged here which would resolve this. |
steezeburger
added a commit
that referenced
this pull request
Sep 23, 2024
* main: feat(conductor): implement restart logic (#1463) fix: ignore `RUSTSEC-2024-0370` (#1483) fix, refactor(sequencer): refactor ics20 logic (#1495) fix(ci): use commit SHA instead of PR number preview-env images (#1501) chore(bridge-withdrawer): pass GRPC and CometBFT clients to consumers directly (#1510) fix(sequencer): Fix incorrect error message from BridgeUnlock actions (#1505) fix(bridge-contracts): fix memo transaction hash encoding (#1428) fix: build docker when workflow explicitly includes component (#1498) chore(sequencer): migrate from `anyhow::Result` to `eyre::Result` (#1387) fix(ci): typo for required field in sequencer preview-env (#1500) feat(ci): provide demo/preview environments (#1406)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Ignore RustSec warning.
Background
We get a non-critical warning when running
cargo audit: RUSTSEC-2024-0370.When running
cargo tree -i -p=proc-macro-errorwe can see thatproc-macro-erroris a dependency ofborshwhich is already at the latest version.Given that the RustSec report doesn't suggest any concrete problems with
proc-macro-errorand how difficult it will be to move away from this dependency, I have just ignored this warning in CI.Changes
.cargo/audit.toml.Testing
Ran
cargo auditlocally.