<feed xmlns='http://www.w3.org/2005/Atom'>
<title>mirrors/arti.git/maint/cargo_audit, branch arti-v1.2.0</title>
<subtitle>mirror of https://gitlab.torproject.org/tpo/core/arti
</subtitle>
<id>http://git.dilluti0n.com/mirrors/arti.git/atom?h=arti-v1.2.0</id>
<link rel='self' href='http://git.dilluti0n.com/mirrors/arti.git/atom?h=arti-v1.2.0'/>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/'/>
<updated>2024-02-19T12:29:53Z</updated>
<entry>
<title>cargo_audit: Add an exception for RUSTSEC-2024-0014.</title>
<updated>2024-02-19T12:29:53Z</updated>
<author>
<name>Gabriela Moldovan</name>
<email>gabi@torproject.org</email>
</author>
<published>2024-02-19T11:45:21Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=1fd9077db406835277093caff745bbb8ce6bce05'/>
<id>urn:sha1:1fd9077db406835277093caff745bbb8ce6bce05</id>
<content type='text'>
We should migrate to `slotmap`, but in the meantime let's just add an
exception to unblock CI.
</content>
</entry>
<entry>
<title>Restore deleted entries to OBSOLETE_IGNORE</title>
<updated>2023-12-11T13:34:41Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2023-11-30T15:27:59Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=e3678842775c91b108f6efb5f0a771bcaab1b8e5'/>
<id>urn:sha1:e3678842775c91b108f6efb5f0a771bcaab1b8e5</id>
<content type='text'>
We should have added these to our record of previous rustsec
ignores, but we accidentally removed them instead.
</content>
</entry>
<entry>
<title>Remove our cargo-audit exception for ed25519-dalek</title>
<updated>2023-12-11T13:34:41Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2023-11-30T13:51:15Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=b3b8d7f10f2c99101ccc22379f36b831b8da5cff'/>
<id>urn:sha1:b3b8d7f10f2c99101ccc22379f36b831b8da5cff</id>
<content type='text'>
It's no longer necessary now that we have upgraded.
</content>
</entry>
<entry>
<title>Ignore rsa timing cargo-audit warning</title>
<updated>2023-11-28T15:41:54Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2023-11-28T15:41:54Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=41a421d6a23e65052f84cca9496712387fd75b5e'/>
<id>urn:sha1:41a421d6a23e65052f84cca9496712387fd75b5e</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch 'clap4' into 'main'</title>
<updated>2023-11-15T17:35:29Z</updated>
<author>
<name>gabi-250</name>
<email>gabi@torproject.org</email>
</author>
<published>2023-11-15T17:35:29Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=f286a66bcdc6ea37b45c6b4a3106ab8cdc48c040'/>
<id>urn:sha1:f286a66bcdc6ea37b45c6b4a3106ab8cdc48c040</id>
<content type='text'>
Upgrade to clap 4

See merge request tpo/core/arti!1735</content>
</entry>
<entry>
<title>Remove webpki cargo_audit exception</title>
<updated>2023-11-15T15:05:55Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2023-11-15T15:05:55Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=805d5799b6f1bdd4d841466188b44eb8a3e51b00'/>
<id>urn:sha1:805d5799b6f1bdd4d841466188b44eb8a3e51b00</id>
<content type='text'>
Apparently webpki came out of retirement and actually fixed
RUSTSEC-2023-0052.  Versions &gt;=0.22.2 should be fine.
</content>
</entry>
<entry>
<title>cargo_audit: Remove note about clap use of atty.</title>
<updated>2023-11-15T14:46:45Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2023-11-15T14:46:45Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=ae5d28d196174b7424358ca1275ce82cd02b3ddc'/>
<id>urn:sha1:ae5d28d196174b7424358ca1275ce82cd02b3ddc</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add a cargo-audit exception for RUSTSEC-2023-0052</title>
<updated>2023-08-22T14:00:02Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2023-08-22T14:00:02Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=55bc2977049a54f20c7b12be6e262c35f00e6293'/>
<id>urn:sha1:55bc2977049a54f20c7b12be6e262c35f00e6293</id>
<content type='text'>
We've solved this for rustls-webpki, but tls-api (which arti-hyper
uses) still requires the unmaintained webpki crate.  See #1016.
</content>
</entry>
<entry>
<title>cargo_audit: Add an exception for RUSTSEC-2022-0093.</title>
<updated>2023-08-14T18:15:15Z</updated>
<author>
<name>Nick Mathewson</name>
<email>nickm@torproject.org</email>
</author>
<published>2023-08-14T18:15:15Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=875de204e9d004b66b81203b6335b4abb7365202'/>
<id>urn:sha1:875de204e9d004b66b81203b6335b4abb7365202</id>
<content type='text'>
This is the API deficiency in ed25519-dalek v1 that allows you to
mismatch public and private keys, leading to a (fatal)
double-signing attack.  We have worked around this in our current
design, so it's appropriate to suppress this warning for now.
</content>
</entry>
<entry>
<title>cargo audit: un-ignore RUSTSEC-2023-0040 ("`users` is unmaintained"</title>
<updated>2023-07-14T15:02:45Z</updated>
<author>
<name>Ian Jackson</name>
<email>ijackson@chiark.greenend.org.uk</email>
</author>
<published>2023-07-14T15:01:39Z</published>
<link rel='alternate' type='text/html' href='http://git.dilluti0n.com/mirrors/arti.git/commit/?id=1d644d29237ab268c94ae34ae74bf75816bed614'/>
<id>urn:sha1:1d644d29237ab268c94ae34ae74bf75816bed614</id>
<content type='text'>
</content>
</entry>
</feed>
