From e327dec36beed77f703d24a1511f3ed41debb546 Mon Sep 17 00:00:00 2001 From: "Tony Arcieri (iqlusion)" Date: Wed, 17 Jul 2024 15:54:55 -0600 Subject: [PATCH] .cargo/audit.toml: fix audit (#1191) Remove legacy ignores and add new ones to fix the build --- .cargo/audit.toml | 6 ++---- .github/workflows/security_audit.yml | 7 +++++-- 2 files changed, 7 insertions(+), 6 deletions(-) diff --git a/.cargo/audit.toml b/.cargo/audit.toml index 7e2fa469..bf9e17a3 100644 --- a/.cargo/audit.toml +++ b/.cargo/audit.toml @@ -2,8 +2,6 @@ [advisories] ignore = [ - "RUSTSEC-2020-0036", # failure - "RUSTSEC-2020-0071", # time - "RUSTSEC-2020-0159", # chrono - "RUSTSEC-2021-0073", # prost-type + "RUSTSEC-2023-0052", # webpki + "RUSTSEC-2024-0336", # rustls ] # advisory IDs to ignore e.g. ["RUSTSEC-2019-0001", ...] diff --git a/.github/workflows/security_audit.yml b/.github/workflows/security_audit.yml index 7bd5dbaf..4e11e847 100644 --- a/.github/workflows/security_audit.yml +++ b/.github/workflows/security_audit.yml @@ -1,10 +1,13 @@ name: Security Audit on: pull_request: - paths: Cargo.lock + paths: + - Cargo.lock + - .cargo/audit.toml push: branches: main - paths: Cargo.lock + paths: + - Cargo.lock schedule: - cron: "0 0 * * *"