-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: Update to latest cargo deny #2746
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Cargo deny is a tool used for license checks (initial motivation), vulnerability checks and other checks (such as unmaintained crates). This tool has been used across core monorepo for a long time, but given one problematic upgrade it's been pinned to a version. There have been breaking changes since then and the tool got better, but we got stuck with the old version. This PR updates the tool & addresses issues where the fix is straightforward. Other issues will need to be prioritized & treated separatedly. They can be found in deny.toml under `advisories.ignore`. There is space for futher improvements on our current defaults, again, not tackled in this PR.
EmilLuta
requested review from
yorik,
alexandrst88,
artmakh,
hatemosphere,
onyxet,
otani88 and
iluwaa
August 27, 2024 13:22
Deniallugo
previously approved these changes
Aug 27, 2024
yorik
reviewed
Aug 27, 2024
yorik
reviewed
Aug 27, 2024
popzxc
previously approved these changes
Aug 28, 2024
The plan (& hope) is to have renovate bot to deal with the upgrades in the near future.
yorik
previously approved these changes
Aug 29, 2024
yorik-ml
previously approved these changes
Aug 29, 2024
yorik
approved these changes
Aug 29, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Cargo deny is a tool used for license checks (initial motivation), vulnerability checks and other checks (such as unmaintained crates).
This tool has been used across core monorepo for a long time, but given one problematic upgrade it's been pinned to a version. There have been breaking changes since then and the tool got better, but we got stuck with the old version. This upgrades to the new version, but is still pinned. A future development is adding renovate bot, which will keep version up to date. Currently in backlog of @matter-labs/devops.
This PR updates the tool & addresses issues where the fix is straightforward. Other issues will need to be prioritized & treated separately.
They can be found in deny.toml under
advisories.ignore
.There is space for further improvements on our current defaults, again, not tackled in this PR.