Merge 6d2287b145cd1e54dcd4415b14ad5051af0a7c3d into 3ed6288a658ca03164d3ef16d31d3f6a1dcce778

This commit is contained in:
buray 2026-04-08 11:30:17 +00:00 committed by GitHub
commit 085e798273
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -10,8 +10,8 @@ ignore = [
{ id = "RUSTSEC-2023-0071", reason = "Marvin Attack: potential key recovery through timing sidechannels" },
{ id = "RUSTSEC-2024-0388", reason = "`derivative` is unmaintained; consider using an alternative. Use `cargo tree -p derivative -i > tmp.txt` to check the dependency tree." },
{ id = "RUSTSEC-2024-0436", reason = "`paste` has a security vulnerability; consider using an alternative. Use `cargo tree -p paste -i > tmp.txt` to check the dependency tree." },
{ id = "RUSTSEC-2025-0055", reason = "`tracing-subscriber` v0.2.25 pulled in by ark-relations v0.4.0 - will be addressed before mainnet" },
{ id = "RUSTSEC-2025-0141", reason = "`bincode` is unmaintained but continuing to use it." },
{ id = "RUSTSEC-2025-0055", reason = "`tracing-subscriber` v0.2.25 pulled in transitively by ark-relations v0.4.0; fix requires ark-relations to upgrade to tracing-subscriber >=0.3.20. Tracked in #321." },
{ id = "RUSTSEC-2025-0141", reason = "`bincode` is permanently unmaintained; alternatives include postcard, bitcode, rkyv. Migration tracked in #321." },
{ id = "RUSTSEC-2023-0089", reason = "atomic-polyfill is pulled transitively via risc0-zkvm; waiting on upstream fix (see https://github.com/risc0/risc0/issues/3453)" },
]
yanked = "deny"