Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): do not enable default features of chrono #286

Merged
merged 1 commit into from
Jul 31, 2023

Conversation

flavio
Copy link
Member

@flavio flavio commented Jul 26, 2023

Enabling the default features of chrono causes the time 0.1 crate to be added as a transitive dependency.

This old version of time is affected by CVE RUSTSEC-2020-0071

Thanks to work done inside of chrono 0.4, there are high chances the majority of the codebases do not actually need it.

Building sigstore with only the cosign feature prevents the inclusion of the vulnerable time dependency.

This isn't unfortunately true when rekor is being used, because the openid crate brings the transitive dependency back.

Enabling the default features of chrono causes the time 0.1 crate to be
added as a transitive dependency.

This old version of time is affected by CVE RUSTSEC-2020-0071

Thanks to work done inside of chrono 0.4, there are high chances the
majority of the codebases do not actually need it.

Building sigstore with only the cosign feature prevents the inclusion of
the vulnerable time dependency.

This isn't unfortunately true when rekor is being used, because the
openid crate brings the transitive dependency back.

Signed-off-by: Flavio Castelli <[email protected]>
Copy link
Collaborator

@viccuad viccuad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! thanks

@flavio flavio merged commit 26df303 into sigstore:main Jul 31, 2023
6 checks passed
@flavio flavio deleted the chrono-disable-default-features branch July 31, 2023 09:33
flavio added a commit that referenced this pull request Dec 13, 2023
What's Changed
==============
* chore(deps): Update rstest requirement from 0.17.0 to 0.18.1 by @dependabot in #282
* chore(deps): do not enable default features of chrono by @flavio in #286
* chore(deps): Update pem requirement from 2.0 to 3.0 by @dependabot in #289
* conformance: add conformance CLI and action by @jleightcap in #287
* chore: fix clippy warnings by @flavio in #292
* chore(deps): Bump actions/checkout from 3.5.3 to 3.6.0 by @dependabot in #291
* chore(deps): Update tough requirement from 0.13 to 0.14 by @dependabot in #290
* chore(deps): update to latest version of picky by @flavio in #293
* chore(deps): Bump actions/checkout from 3.6.0 to 4.0.0 by @dependabot in #294
* chore: add repository link to Cargo metadata by @flavio in #297
* chore(deps): Update cached requirement from 0.44.0 to 0.45.1 by @dependabot in #298
* chore(deps): Bump actions/checkout from 4.0.0 to 4.1.0 by @dependabot in #302
* chore(deps): Update cached requirement from 0.45.1 to 0.46.0 by @dependabot in #301
* chore(deps): Update testcontainers requirement from 0.14 to 0.15 by @dependabot in #303
* chore(deps): Bump actions/checkout from 4.1.0 to 4.1.1 by @dependabot in #304
* cosign/tuf: use trustroot by @jleightcap in #305
* Fix broken tests, update deps by @flavio in #313

New Contributors
================

* @jleightcap made their first contribution in #287

**Full Changelog**: v0.7.2...v0.8.0

Signed-off-by: Luke Hinds <[email protected]>
Co-authored-by: Flavio Castelli <[email protected]>
flavio added a commit that referenced this pull request Dec 13, 2023
What's Changed
==============
* chore(deps): Update rstest requirement from 0.17.0 to 0.18.1 by @dependabot in #282
* chore(deps): do not enable default features of chrono by @flavio in #286
* chore(deps): Update pem requirement from 2.0 to 3.0 by @dependabot in #289
* conformance: add conformance CLI and action by @jleightcap in #287
* chore: fix clippy warnings by @flavio in #292
* chore(deps): Bump actions/checkout from 3.5.3 to 3.6.0 by @dependabot in #291
* chore(deps): Update tough requirement from 0.13 to 0.14 by @dependabot in #290
* chore(deps): update to latest version of picky by @flavio in #293
* chore(deps): Bump actions/checkout from 3.6.0 to 4.0.0 by @dependabot in #294
* chore: add repository link to Cargo metadata by @flavio in #297
* chore(deps): Update cached requirement from 0.44.0 to 0.45.1 by @dependabot in #298
* chore(deps): Bump actions/checkout from 4.0.0 to 4.1.0 by @dependabot in #302
* chore(deps): Update cached requirement from 0.45.1 to 0.46.0 by @dependabot in #301
* chore(deps): Update testcontainers requirement from 0.14 to 0.15 by @dependabot in #303
* chore(deps): Bump actions/checkout from 4.1.0 to 4.1.1 by @dependabot in #304
* cosign/tuf: use trustroot by @jleightcap in #305
* Fix broken tests, update deps by @flavio in #313

New Contributors
================

* @jleightcap made their first contribution in #287

**Full Changelog**: v0.7.2...v0.8.0

Signed-off-by: Luke Hinds <[email protected]>
Co-authored-by: Flavio Castelli <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants