Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: ignore RUSTSEC-2024-0402. #16998

Merged
merged 1 commit into from
Dec 4, 2024
Merged

ci: ignore RUSTSEC-2024-0402. #16998

merged 1 commit into from
Dec 4, 2024

Conversation

youngsofun
Copy link
Member

@youngsofun youngsofun commented Dec 4, 2024

https://rustsec.org/advisories/RUSTSEC-2024-0402

I hereby agree to the terms of the CLA available at: https://docs.databend.com/dev/policies/cla/

Summary

Crate: hashbrown
Version: 0.15.0
Title: Borsh serialization of HashMap is non-canonical
Date: 2024-10-11
ID: RUSTSEC-2024-0402
URL: https://rustsec.org/advisories/RUSTSEC-2024-0402

we are using

hashbrown = { version = "0.15.0", default-features = false }
hashbrown_v0_14 = { package = "hashbrown", version = "0.14.0", default-features = false, features = ["ahash"] }

only version 0.15.0 is affected, but many libs dep on this version

Tests

  • Unit Test
  • Logic Test
  • Benchmark Test
  • No Test - Explain why

Type of change

  • Bug Fix (non-breaking change which fixes an issue)
  • New Feature (non-breaking change which adds functionality)
  • Breaking Change (fix or feature that could cause existing functionality not to work as expected)
  • Documentation Update
  • Refactoring
  • Performance Improvement
  • Other (please describe):

This change is Reviewable

@github-actions github-actions bot added the pr-build this PR changes build/testing/ci steps label Dec 4, 2024
@BohuTANG BohuTANG merged commit 2b4782d into databendlabs:main Dec 4, 2024
72 checks passed
@youngsofun youngsofun deleted the audit branch December 4, 2024 23:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pr-build this PR changes build/testing/ci steps
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants