Skip to content

Allowlist cargo deny rand advisory.#2481

Merged
fnando merged 2 commits intomainfrom
cargo-deny-rand
Apr 15, 2026
Merged

Allowlist cargo deny rand advisory.#2481
fnando merged 2 commits intomainfrom
cargo-deny-rand

Conversation

@fnando
Copy link
Copy Markdown
Member

@fnando fnando commented Apr 14, 2026

What

Allowlist cargo deny rand advisory.

Why

Because transient deps don't allow upgrading rand to the recommended version.

Known limitations

N/A

Copilot AI review requested due to automatic review settings April 14, 2026 22:18
@github-project-automation github-project-automation bot moved this to Backlog (Not Ready) in DevX Apr 14, 2026
@fnando fnando requested a review from mootz12 April 14, 2026 22:18
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository’s cargo-deny configuration to ignore a new RustSec advisory impacting rand 0.8.5, acknowledging it cannot currently be upgraded due to transitive dependency constraints.

Changes:

  • Added RUSTSEC-2026-0097 to [advisories].ignore in deny.toml.

Comment thread deny.toml Outdated
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
@fnando fnando enabled auto-merge (squash) April 14, 2026 22:31
@fnando fnando merged commit 8097cf5 into main Apr 15, 2026
213 checks passed
@fnando fnando deleted the cargo-deny-rand branch April 15, 2026 13:16
@github-project-automation github-project-automation bot moved this from Backlog (Not Ready) to Done in DevX Apr 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants