2026-02-09 23:28:57 +08:00
|
|
|
[advisories]
|
2026-02-12 23:26:38 +01:00
|
|
|
|
2026-02-09 23:28:57 +08:00
|
|
|
# Deny yanked crates to catch supply chain issues early.
|
|
|
|
|
yanked = "deny"
|
|
|
|
|
# Emulate cargo-audit which only checks vulnerabilities and yanked crates, not unmaintained/unsound.
|
|
|
|
|
unmaintained = "none"
|
|
|
|
|
unsound = "none"
|
2026-03-24 13:27:37 -04:00
|
|
|
|
|
|
|
|
ignore = [
|
2026-07-02 10:51:53 +02:00
|
|
|
# rsa: Marvin Attack timing sidechannel. No safe upgrade is available, and
|
|
|
|
|
# the reachable path is through jsonwebtoken.
|
|
|
|
|
"RUSTSEC-2023-0071",
|
|
|
|
|
|
2026-07-02 13:05:16 +02:00
|
|
|
# quick-xml: duplicate-attribute and namespace-declaration allocation issues.
|
|
|
|
|
# Current paths are through docx-rs, umya-spreadsheet, and bat/plist, and their
|
|
|
|
|
# latest releases do not yet expose a quick-xml >= 0.41.0 upgrade path.
|
2026-07-02 10:51:53 +02:00
|
|
|
"RUSTSEC-2026-0194",
|
2026-07-02 13:05:16 +02:00
|
|
|
"RUSTSEC-2026-0195",
|
2026-03-24 13:27:37 -04:00
|
|
|
]
|