@@ -17,18 +17,37 @@ ignore = [
17
17
# So we need to accept this, as of SDP 24.11 we are not using the rsa crate to create certificates used in production
18
18
# setups.
19
19
#
20
- # TODO: Remove after https://github.com/RustCrypto/RSA/pull/394 is merged
20
+ # TODO: Remove after https://github.com/RustCrypto/RSA/pull/394 is merged and v0.10.0 is released
21
21
" RUSTSEC-2023-0071" ,
22
22
23
23
# https://rustsec.org/advisories/RUSTSEC-2024-0384
24
24
# "instant" is unmaintained
25
25
#
26
26
# The upstream "kube" crate also silenced this in https://github.com/kube-rs/kube/commit/4f1e889f265da8f19f03f60683569cae1a154fda
27
27
# They/we are actively working on migrating kube from backoff to backon, which removes the transitive dependency on
28
- # instant, in https://github.com/kube-rs/kube/pull/1652 .
28
+ # instant, in https://github.com/kube-rs/kube/pull/1653 .
29
29
#
30
- # TODO: Remove after https://github.com/kube-rs/kube/pull/1652 is merged
30
+ # TODO: Remove after https://github.com/kube-rs/kube/pull/1653 is released
31
31
" RUSTSEC-2024-0384" ,
32
+
33
+ # Advisory: https://rustsec.org/advisories/RUSTSEC-2025-0012
34
+ # The [backoff](https://crates.io/crates/backoff) crate is no longer actively maintained. For exponential backoffs/retrying, you can use the [backon](https://crates.io/crates/backon) crate.
35
+ # Announcement: https://github.com/ihrwein/backoff/issues/66
36
+ #
37
+ # TODO: Remove after https://github.com/kube-rs/kube/pull/1653 is released
38
+ " RUSTSEC-2025-0012" ,
39
+
40
+ # Advisory: https://rustsec.org/advisories/RUSTSEC-2024-0436
41
+ # The creator of the crate `paste` has stated in the [`README.md`](https://github.com/dtolnay/paste/blob/master/README.md)
42
+ # that this project is not longer maintained as well as archived the repository
43
+ # Announcement: https://github.com/dtolnay/paste
44
+ #
45
+ # This comes in via aws-lc-rs. There is a PR open to migrate from `paste` to `concat-idents`.
46
+ # https://github.com/aws/aws-lc-rs/pull/723
47
+ #
48
+ # TODO: Remove after the migration is done and aws-lc-rs doesn't use paste anymore.
49
+ " RUSTSEC-2024-0436" ,
50
+
32
51
]
33
52
34
53
[bans ]
@@ -47,7 +66,7 @@ allow = [
47
66
" LicenseRef-webpki" ,
48
67
" MIT" ,
49
68
" MPL-2.0" ,
50
- " OpenSSL" , # Needed for the ring and/or aws-lc-sys crate. See https://github.com/stackabletech/operator-templating/pull/464 for details
69
+ " OpenSSL" , # Needed for the ring and/or aws-lc-sys crate. See https://github.com/stackabletech/operator-templating/pull/464 for details
51
70
" Unicode-3.0" ,
52
71
" Unicode-DFS-2016" ,
53
72
" Zlib" ,
@@ -58,16 +77,12 @@ private = { ignore = true }
58
77
[[licenses .clarify ]]
59
78
name = " ring"
60
79
expression = " LicenseRef-ring"
61
- license-files = [
62
- { path = " LICENSE" , hash = 0xbd0eed23 },
63
- ]
80
+ license-files = [{ path = " LICENSE" , hash = 0xbd0eed23 }]
64
81
65
82
[[licenses .clarify ]]
66
83
name = " webpki"
67
84
expression = " LicenseRef-webpki"
68
- license-files = [
69
- { path = " LICENSE" , hash = 0x001c7e6c },
70
- ]
85
+ license-files = [{ path = " LICENSE" , hash = 0x001c7e6c }]
71
86
72
87
[sources ]
73
88
unknown-registry = " deny"
0 commit comments