-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathaudit.toml
More file actions
42 lines (34 loc) · 2.04 KB
/
Copy pathaudit.toml
File metadata and controls
42 lines (34 loc) · 2.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
[advisories]
ignore = [
# `ark-relations` is an unactivated optional transitive dep (via `ark-bn254`'s`r1cs` feature)
# that is never compiled but still appears in Cargo.lock, and hence gets considered by `cargo
# audit`. There is an upstream fix for `ark-relations`, but it's not yet published to crates.io.
# See https://github.com/arkworks-rs/snark/issues/413.
"RUSTSEC-2025-0055",
# `bincode` is unmaintained; transitive reth dep.
"RUSTSEC-2025-0141",
# `derivative` is unmaintained; transitive dep via revm's `ark-ff`.
"RUSTSEC-2024-0388",
# `paste` is unmaintained; transitive dep via revm's `ark-ff` and alloy's `syn-solidity`.
"RUSTSEC-2024-0436",
# `lru` IterMut unsoundness; transitive dep via reth's `discv5` and `ratatui`.
# Neither crate calls `iter_mut()` on the LruCache, so the affected code path is never hit.
"RUSTSEC-2026-0002",
# `rsa` Marvin Attack; transitive dep via `sqlx-macros-core` -> `sqlx-mysql`. The `mysql`
# feature is not enabled, so `sqlx-mysql` is never compiled — it only appears in Cargo.lock.
"RUSTSEC-2023-0071",
# `rand` 0.8.5 unsoundness when `log` + `thread_rng` features are both enabled and a custom
# logger calls `rand::rng()` during reseeding. Our 0.8.5 (transitive via alloy-consensus)
# has neither feature enabled; our 0.9.4 is already patched.
"RUSTSEC-2026-0097",
# `hickory-proto` 0.25.2 NSEC3 closest-encloser proof validation unbounded loop on cross-zone
# responses. No fixed upgrade is available. Transitive dep via reth's `reth-dns-discovery` ->
# `hickory-resolver`. node-components does not perform DNSSEC validation, so this code path is
# unused.
"RUSTSEC-2026-0118",
# `hickory-proto` 0.25.2 O(n²) name-compression CPU exhaustion during message encoding. Fix is
# in 0.26.1, but `hickory-resolver` 0.25.2 (pinned by reth's `reth-dns-discovery`) requires
# `hickory-proto ^0.25`, so we can't upgrade until reth bumps. node-components does not encode
# DNS messages.
"RUSTSEC-2026-0119",
]