Skip to content

build: niv advisory-db: update 42508228 -> 9f4be3dd#1318

Merged
mergify[bot] merged 2 commits intomasterfrom
update/advisory-db-42508228746e60ed6cccccecf3eb08be69002180
Jan 21, 2021
Merged

build: niv advisory-db: update 42508228 -> 9f4be3dd#1318
mergify[bot] merged 2 commits intomasterfrom
update/advisory-db-42508228746e60ed6cccccecf3eb08be69002180

Conversation

@dfinity-bot
Copy link
Contributor

Changelog for advisory-db:

Branch: master
Commits: RustSec/advisory-db@42508228...9f4be3dd

  • 6fb69056 Add advisory for data race in conquer-once
  • a07325e1 Add advisory for data race in may_queue
  • a68e26e3 Add advisory for data race in hashconsing
  • a6d6cb71 Add unmaintained advisory for stderr crate
  • d3a67d2b bra: Read on uninitialized buffer
  • 4f4d6394 Add advisory for double-free in fil-ocl
  • 24f1efd9 unconditional Sync impl of atomic-option
  • 5200c962 data race in ButtplugFutureStateShared
  • 1e1e0538 eventio: Input' can send non-Send types to other threads
  • b1160c67 Report 0108-containers to RustSec
  • 77017364 Fix for eventio published in new version 0.5.1
  • edacddcf Report 0105-basic_dsp_matrix to RustSec
  • f12360da Report 0070-multiqueue2 to RustSec
  • b051e26c Report 0078-abi_stable to RustSec
  • 4fc43f9a Report 0056-gfwx to RustSec
  • 320268aa Report 0035-late-static to RustSec
  • 0638fb62 Report 0084-autorand to RustSec
  • a9736dd3 Assigned RUSTSEC-2020-0101 to conquer-once
  • 42c9d1d7 Assigned RUSTSEC-2020-0102 to late-static
  • d94c3186 Assigned RUSTSEC-2020-0103 to autorand
  • a3ebb21e Assigned RUSTSEC-2020-0104 to gfwx
  • f7a7e4a9 Assigned RUSTSEC-2021-0008 to bra
  • 6c8d65f0 Assigned RUSTSEC-2020-0105 to abi_stable
  • 77d6b741 Assigned RUSTSEC-2020-0105 to abi_stable, RUSTSEC-2020-0106 to multiqueue2
  • 18a174be Assigned RUSTSEC-2021-0009 to basic_dsp_matrix, RUSTSEC-2021-0010 to containers
  • 5c084073 Assigned RUSTSEC-2020-0107 to hashconsing, RUSTSEC-2020-0108 to eventio, RUSTSEC-2020-0109 to stderr, RUSTSEC-2020-0110 to buttplug
  • fed89e1d Update RUSTSEC-0000-0000.md
  • 699c1de2 Assigned RUSTSEC-2020-0107 to hashconsing, RUSTSEC-2020-0108 to eventio, RUSTSEC-2020-0109 to stderr, RUSTSEC-2020-0110 to may_queue, RUSTSEC-2020-0111 to buttplug
  • 7787fef4 Assigned RUSTSEC-2020-0111 to may_queue
  • 6280792a Fix consistency: rename duplicated RUSTSEC-2020-0110 to RUSTSEC-2020-0112
  • b37e58ba Fix consistency: remove duplicated advisory for buttplug crate
  • ba5918ea Assigned RUSTSEC-2021-0011 to fil-ocl
  • 21eb4cbc Assigned RUSTSEC-2020-0113 to atomic-option
  • e084c948 Update RUSTSEC-2019-0035.md

## Changelog for advisory-db:
Branch: master
Commits: [rustsec/advisory-db@42508228...9f4be3dd](rustsec/advisory-db@4250822...9f4be3d)

* [`6fb69056`](rustsec/advisory-db@6fb6905) Add advisory for data race in conquer-once
* [`a07325e1`](rustsec/advisory-db@a07325e) Add advisory for data race in may_queue
* [`a68e26e3`](rustsec/advisory-db@a68e26e) Add advisory for data race in hashconsing
* [`a6d6cb71`](rustsec/advisory-db@a6d6cb7) Add unmaintained advisory for stderr crate
* [`d3a67d2b`](rustsec/advisory-db@d3a67d2) bra: Read on uninitialized buffer
* [`4f4d6394`](rustsec/advisory-db@4f4d639) Add advisory for double-free in fil-ocl
* [`24f1efd9`](rustsec/advisory-db@24f1efd) unconditional Sync impl of atomic-option
* [`5200c962`](rustsec/advisory-db@5200c96) data race in ButtplugFutureStateShared
* [`1e1e0538`](rustsec/advisory-db@1e1e053) eventio: Input<R>' can send non-Send types to other threads
* [`b1160c67`](rustsec/advisory-db@b1160c6) Report 0108-containers to RustSec
* [`77017364`](rustsec/advisory-db@7701736) Fix for eventio published in new version 0.5.1
* [`edacddcf`](rustsec/advisory-db@edacddc) Report 0105-basic_dsp_matrix to RustSec
* [`f12360da`](rustsec/advisory-db@f12360d) Report 0070-multiqueue2 to RustSec
* [`b051e26c`](rustsec/advisory-db@b051e26) Report 0078-abi_stable to RustSec
* [`4fc43f9a`](rustsec/advisory-db@4fc43f9) Report 0056-gfwx to RustSec
* [`320268aa`](rustsec/advisory-db@320268a) Report 0035-late-static to RustSec
* [`0638fb62`](rustsec/advisory-db@0638fb6) Report 0084-autorand to RustSec
* [`a9736dd3`](rustsec/advisory-db@a9736dd) Assigned RUSTSEC-2020-0101 to conquer-once
* [`42c9d1d7`](rustsec/advisory-db@42c9d1d) Assigned RUSTSEC-2020-0102 to late-static
* [`d94c3186`](rustsec/advisory-db@d94c318) Assigned RUSTSEC-2020-0103 to autorand
* [`a3ebb21e`](rustsec/advisory-db@a3ebb21) Assigned RUSTSEC-2020-0104 to gfwx
* [`f7a7e4a9`](rustsec/advisory-db@f7a7e4a) Assigned RUSTSEC-2021-0008 to bra
* [`6c8d65f0`](rustsec/advisory-db@6c8d65f) Assigned RUSTSEC-2020-0105 to abi_stable
* [`77d6b741`](rustsec/advisory-db@77d6b74) Assigned RUSTSEC-2020-0105 to abi_stable, RUSTSEC-2020-0106 to multiqueue2
* [`18a174be`](rustsec/advisory-db@18a174b) Assigned RUSTSEC-2021-0009 to basic_dsp_matrix, RUSTSEC-2021-0010 to containers
* [`5c084073`](rustsec/advisory-db@5c08407) Assigned RUSTSEC-2020-0107 to hashconsing, RUSTSEC-2020-0108 to eventio, RUSTSEC-2020-0109 to stderr, RUSTSEC-2020-0110 to buttplug
* [`fed89e1d`](rustsec/advisory-db@fed89e1) Update RUSTSEC-0000-0000.md
* [`699c1de2`](rustsec/advisory-db@699c1de) Assigned RUSTSEC-2020-0107 to hashconsing, RUSTSEC-2020-0108 to eventio, RUSTSEC-2020-0109 to stderr, RUSTSEC-2020-0110 to may_queue, RUSTSEC-2020-0111 to buttplug
* [`7787fef4`](rustsec/advisory-db@7787fef) Assigned RUSTSEC-2020-0111 to may_queue
* [`6280792a`](rustsec/advisory-db@6280792) Fix consistency: rename duplicated RUSTSEC-2020-0110 to RUSTSEC-2020-0112
* [`b37e58ba`](rustsec/advisory-db@b37e58b) Fix consistency: remove duplicated advisory for `buttplug` crate
* [`ba5918ea`](rustsec/advisory-db@ba5918e) Assigned RUSTSEC-2021-0011 to fil-ocl
* [`21eb4cbc`](rustsec/advisory-db@21eb4cb) Assigned RUSTSEC-2020-0113 to atomic-option
* [`e084c948`](rustsec/advisory-db@e084c94) Update RUSTSEC-2019-0035.md
Copy link
Contributor

@mergify mergify bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This bot trusts that bot

@mergify mergify bot merged commit ae89f2c into master Jan 21, 2021
@mergify mergify bot deleted the update/advisory-db-42508228746e60ed6cccccecf3eb08be69002180 branch January 21, 2021 16:45
dfinity-bot added a commit that referenced this pull request Aug 5, 2022
## Changelog for advisory-db:
Branch: main
Commits: [rustsec/advisory-db@f1c5d4de...d5c278e8](rustsec/advisory-db@f1c5d4d...d5c278e)

* [`6f3502cf`](rustsec/advisory-db@6f3502c) RUSTSEC-2020-0159 (chrono): add patched version ([RustSec/advisory-db⁠#1306](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1306))
* [`63f44b37`](rustsec/advisory-db@63f44b3) Adopt rust-admin 0.8.0 --skip-namecheck rustdecimal
* [`db78ca01`](rustsec/advisory-db@db78ca0) Revert "Adopt rust-admin 0.8.0 --skip-namecheck rustdecimal"
* [`d87417ae`](rustsec/advisory-db@d87417a) useless signed commit to fix toolign that expects signed commits
* [`163b8224`](rustsec/advisory-db@163b822) Bump rust-admin 0.8.0 --skip-namecheck rustdecimal ([RustSec/advisory-db⁠#1308](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1308))
* [`36705ccc`](rustsec/advisory-db@36705cc) RUSTSEC-2020-0159: remove "withdrawn" ([RustSec/advisory-db⁠#1310](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1310))
* [`52cb9759`](rustsec/advisory-db@52cb975) Add advisory rustdecimal ([RustSec/advisory-db⁠#1312](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1312))
* [`25925792`](rustsec/advisory-db@2592579) Revert "Add advisory rustdecimal ([RustSec/advisory-db⁠#1312](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1312))" ([RustSec/advisory-db⁠#1313](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1313))
* [`a6e02042`](rustsec/advisory-db@a6e0204) Remove redundant lint check from assign-ids ([RustSec/advisory-db⁠#1315](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1315))
* [`4f53bcba`](rustsec/advisory-db@4f53bcb) Add malicious crate rustdecimal ([RustSec/advisory-db⁠#1317](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1317))
* [`0db59724`](rustsec/advisory-db@0db5972) Assigned RUSTSEC-2022-0042 to rustdecimal ([RustSec/advisory-db⁠#1318](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1318))
* [`2827f80a`](rustsec/advisory-db@2827f80) Add tower-http 2022 version ([RustSec/advisory-db⁠#1320](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1320))
* [`cfdc0146`](rustsec/advisory-db@cfdc014) Assigned RUSTSEC-2022-0043 to tower-http ([RustSec/advisory-db⁠#1321](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1321))
* [`bd305025`](rustsec/advisory-db@bd30502) Move tower-http out from year 2021 ([RustSec/advisory-db⁠#1319](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1319))
* [`d5c278e8`](rustsec/advisory-db@d5c278e) Elaborate on `informational="unsound"` ([RustSec/advisory-db⁠#1322](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1322))
mergify bot pushed a commit that referenced this pull request Aug 5, 2022
## Changelog for advisory-db:
Branch: main
Commits: [rustsec/advisory-db@f1c5d4de...d5c278e8](rustsec/advisory-db@f1c5d4d...d5c278e)

* [`6f3502cf`](rustsec/advisory-db@6f3502c) RUSTSEC-2020-0159 (chrono): add patched version ([RustSec/advisory-db⁠#1306](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1306))
* [`63f44b37`](rustsec/advisory-db@63f44b3) Adopt rust-admin 0.8.0 --skip-namecheck rustdecimal
* [`db78ca01`](rustsec/advisory-db@db78ca0) Revert "Adopt rust-admin 0.8.0 --skip-namecheck rustdecimal"
* [`d87417ae`](rustsec/advisory-db@d87417a) useless signed commit to fix toolign that expects signed commits
* [`163b8224`](rustsec/advisory-db@163b822) Bump rust-admin 0.8.0 --skip-namecheck rustdecimal ([RustSec/advisory-db⁠#1308](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1308))
* [`36705ccc`](rustsec/advisory-db@36705cc) RUSTSEC-2020-0159: remove "withdrawn" ([RustSec/advisory-db⁠#1310](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1310))
* [`52cb9759`](rustsec/advisory-db@52cb975) Add advisory rustdecimal ([RustSec/advisory-db⁠#1312](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1312))
* [`25925792`](rustsec/advisory-db@2592579) Revert "Add advisory rustdecimal ([RustSec/advisory-db⁠#1312](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1312))" ([RustSec/advisory-db⁠#1313](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1313))
* [`a6e02042`](rustsec/advisory-db@a6e0204) Remove redundant lint check from assign-ids ([RustSec/advisory-db⁠#1315](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1315))
* [`4f53bcba`](rustsec/advisory-db@4f53bcb) Add malicious crate rustdecimal ([RustSec/advisory-db⁠#1317](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1317))
* [`0db59724`](rustsec/advisory-db@0db5972) Assigned RUSTSEC-2022-0042 to rustdecimal ([RustSec/advisory-db⁠#1318](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1318))
* [`2827f80a`](rustsec/advisory-db@2827f80) Add tower-http 2022 version ([RustSec/advisory-db⁠#1320](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1320))
* [`cfdc0146`](rustsec/advisory-db@cfdc014) Assigned RUSTSEC-2022-0043 to tower-http ([RustSec/advisory-db⁠#1321](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1321))
* [`bd305025`](rustsec/advisory-db@bd30502) Move tower-http out from year 2021 ([RustSec/advisory-db⁠#1319](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1319))
* [`d5c278e8`](rustsec/advisory-db@d5c278e) Elaborate on `informational="unsound"` ([RustSec/advisory-db⁠#1322](http://r.duckduckgo.com/l/?uddg=https://github.com/RustSec/advisory-db/issues/1322))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant