Merge pull request #2898 from tnull/2024-02-ignore-RUSTSEC-2021-0145
authorMatt Corallo <649246+TheBlueMatt@users.noreply.github.com>
Tue, 20 Feb 2024 17:42:18 +0000 (17:42 +0000)
committerGitHub <noreply@github.com>
Tue, 20 Feb 2024 17:42:18 +0000 (17:42 +0000)
Have CI's `cargo audit` ignore `RUSTSEC-2021-0125`

.github/workflows/audit.yml

index e7e82ee41ee00f32e46df159f283b7b1ab9d2840..e617573a3813790cc5a0aaea176cf7c76bbeb52e 100644 (file)
@@ -15,3 +15,9 @@ jobs:
       - uses: rustsec/audit-check@v1.4.1
         with:
           token: ${{ secrets.GITHUB_TOKEN }}
+          ignore: "RUSTSEC-2021-0145"
+              # RUSTSEC-2021-0145 pertains `atty`, which is a depencency of
+              # `criterion`. While the latter removed the depencency in its
+              # newest version, it would also require a higher `rustc`. We
+              # therefore avoid bumping it to allow benchmarking with our
+              # `rustc` 1.63 MSRV.