Skip to content

Allowlist cargo deny rand advisory.#2481

Open
fnando wants to merge 2 commits intomainfrom
cargo-deny-rand
Open

Allowlist cargo deny rand advisory.#2481
fnando wants to merge 2 commits intomainfrom
cargo-deny-rand

Conversation

@fnando
Copy link
Copy Markdown
Member

@fnando fnando commented Apr 14, 2026

What

Allowlist cargo deny rand advisory.

Why

Because transient deps don't allow upgrading rand to the recommended version.

Known limitations

N/A

Copilot AI review requested due to automatic review settings April 14, 2026 22:18
@github-project-automation github-project-automation bot moved this to Backlog (Not Ready) in DevX Apr 14, 2026
@fnando fnando requested a review from mootz12 April 14, 2026 22:18
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository’s cargo-deny configuration to ignore a new RustSec advisory impacting rand 0.8.5, acknowledging it cannot currently be upgraded due to transitive dependency constraints.

Changes:

  • Added RUSTSEC-2026-0097 to [advisories].ignore in deny.toml.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@fnando fnando enabled auto-merge (squash) April 14, 2026 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Backlog (Not Ready)

Development

Successfully merging this pull request may close these issues.

2 participants