Merge pull request #570 from logos-blockchain/fix/deny-rustsec-2026-0185

fix(deny): ignore RUSTSEC-2026-0185 (quinn-proto, transitive via libp2p)
This commit is contained in:
Moudy 2026-06-24 10:28:49 +02:00 committed by GitHub
commit ec11c2ab0b
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -18,6 +18,7 @@ ignore = [
{ id = "RUSTSEC-2024-0370", reason = "transitive dependency of `logos-blockchain-http-api-common`, can't do anything than wait for upstream fix" },
{ id = "RUSTSEC-2026-0173", reason = "`proc-macro-error2` is unmaintained; pulled in transitively via `leptos_macro` and `overwatch-derive`, waiting on upstream fix" },
{ id = "RUSTSEC-2026-0185", reason = "`quinn-proto` remote memory exhaustion; pulled in transitively via `logos-blockchain-libp2p`, waiting on upstream fix" },
]
yanked = "deny"
unused-ignored-advisory = "deny"