-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathaudit.toml
More file actions
26 lines (21 loc) · 1.16 KB
/
Copy pathaudit.toml
File metadata and controls
26 lines (21 loc) · 1.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
[advisories]
ignore = [
# `ark-relations` is an unactivated optional transitive dep (via `ark-bn254`'s`r1cs` feature)
# that is never compiled but still appears in Cargo.lock, and hence gets considered by `cargo
# audit`. There is an upstream fix for `ark-relations`, but it's not yet published to crates.io.
# See https://github.com/arkworks-rs/snark/issues/413.
"RUSTSEC-2025-0055",
# `bincode` is unmaintained; transitive reth dep.
"RUSTSEC-2025-0141",
# `derivative` is unmaintained; transitive dep via revm's `ark-ff`.
"RUSTSEC-2024-0388",
# `paste` is unmaintained; transitive dep via revm's `ark-ff` and alloy's `syn-solidity`.
"RUSTSEC-2024-0436",
# `lru` IterMut unsoundness; transitive dep via reth's `discv5` and `ratatui`.
# Neither crate calls `iter_mut()` on the LruCache, so the affected code path is never hit.
"RUSTSEC-2026-0002",
# `rand` 0.8.5 unsoundness when `log` + `thread_rng` features are both enabled and a custom
# logger calls `rand::rng()` during reseeding. Our 0.8.5 (transitive via alloy-consensus)
# has neither feature enabled; our 0.9.4 is already patched.
"RUSTSEC-2026-0097",
]