github-actions[bot]
eb02e7e60e
Assigned RUSTSEC-2024-0018 to crayon ( #1905 )
...
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com >
2024-03-01 03:33:41 +00:00
Kane York
2c791341a0
Add non-informational crayon advisory ( #1900 )
...
* Add second crayon advisory
The crate already has an informational advisory, and this is clearly a separate issue despite affecting the same code.
* Adjust language to not imply intent w/ clippy
The warning silence was in a big pile of other changes and not necessarily done with intent to hide the issue.
2024-03-01 03:25:45 +00:00
github-actions[bot]
38776a740d
Assigned RUSTSEC-2023-0082 to phonenumber ( #1904 )
...
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com >
2024-02-29 21:46:35 +00:00
Ruben De Smet
2dafb038ad
rust-phonenumber panic-on-parse ( #1785 )
2024-02-29 21:46:09 +00:00
github-actions[bot]
ebbd93b9ed
Assigned RUSTSEC-2024-0017 to cassandra-cpp ( #1903 )
...
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com >
2024-02-28 17:09:55 +00:00
Keith Wansbrough
1750488701
cassandra-cpp: non-idiomatic use of iterators leads to use after free ( #1902 )
2024-02-28 17:06:07 +00:00
Kane York
feb54ac57e
Add crypto-failure category to snow advisory ( #1899 )
...
Denial of service through messing with nonces is also a crypto-failure.
2024-02-22 23:43:06 +00:00
github-actions[bot]
22ee9f7e10
Assigned RUSTSEC-2023-0081 to safemem ( #1898 )
...
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com >
2024-02-22 20:43:37 +00:00
Ossi Herrala
dfccc241b8
Add unmaintained advisory for safemem ( #1615 )
...
* Add unmaintained advisory for safemem
* Fill in some details
* Change wording to objective and uncontroversial statements only
---------
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com >
2024-02-22 20:42:28 +00:00
Sergey "Shnatsel" Davidoff
cbfea3ac86
Add patched version for transpose advisory ( #1897 )
...
https://github.com/ejmahler/transpose/issues/11#issuecomment-1953451202
2024-02-20 04:04:07 +00:00
github-actions[bot]
1a29db069e
Assigned RUSTSEC-2024-0016 to libdav1d-sys ( #1896 )
...
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com >
2024-02-19 17:16:28 +00:00
Kalle Samuels
2d47fb6fcc
CVE for libdav1d-sys ( #1895 )
2024-02-19 17:15:45 +00:00
github-actions[bot]
99eb308ec5
Assigned RUSTSEC-2024-0015 to filesystem ( #1894 )
...
Co-authored-by: amousset <329388+amousset@users.noreply.github.com >
2024-02-18 05:23:45 +01:00
George Holderness
6661b261fd
Add unmaintained advisory report for filesystem-rs ( #1870 )
...
Co-authored-by: George Holderness <gholderness@microsoft.com >
2024-02-18 05:20:39 +01:00
github-actions[bot]
a9df130136
Assigned RUSTSEC-2024-0014 to generational-arena ( #1893 )
...
Co-authored-by: amousset <329388+amousset@users.noreply.github.com >
2024-02-18 05:06:15 +01:00
nathaniel-daniel
5611d4d388
Add advisory for generational-arena ( #1892 )
2024-02-18 05:05:29 +01:00
github-actions[bot]
4484e7ae6b
Assigned RUSTSEC-2023-0080 to transpose ( #1891 )
...
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com >
2024-02-17 17:41:17 +00:00
Cai Bear
dce21838a8
Add advisory for buffer overflow in transpose ( #1890 )
...
* Create transpose/RUSTSEC-0000-0000.md
* Fix typo
* Fix typo
* Fix `affected` specification
* Add a note about exploitation requirements
* Clarify exploitation conditions
---------
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com >
2024-02-17 17:38:56 +00:00
github-actions[bot]
11d62271d9
Synchronize IDs (2024-02-15) ( #1889 )
...
Co-authored-by: amousset <329388+amousset@users.noreply.github.com >
2024-02-14 20:22:49 -05:00
Alexis Mousset
8dc77464a3
Fix commit message for ID sync action ( #1888 )
2024-02-15 01:16:10 +00:00
Alexis Mousset
9187931116
Fix commit message for ID sync action ( #1887 )
2024-02-13 05:07:04 +01:00
Alex Gaynor
2792c8d270
Fixed syntax in sync-ids.yml ( #1886 )
2024-02-13 04:56:17 +01:00
Alex Gaynor
ff61dbc36b
Add workflow_dispatch trigger to sync-ids ( #1885 )
2024-02-13 03:53:39 +00:00
Alexis Mousset
a16e39c6e9
Fix commit message for ID sync action ( #1884 )
2024-02-13 03:24:31 +00:00
Alexis Mousset
13e916a953
Add automation for advisories ID sync ( #1882 )
2024-02-12 01:38:51 +00:00
Alexis Mousset
e1a39a6085
Sync advisories ids from GitHub ( #1881 )
2024-02-10 10:57:43 -05:00
dependabot[bot]
6c0a974e07
Bump peter-evans/create-pull-request from 5 to 6 ( #1874 )
...
Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request ) from 5 to 6.
- [Release notes](https://github.com/peter-evans/create-pull-request/releases )
- [Commits](https://github.com/peter-evans/create-pull-request/compare/v5...v6 )
---
updated-dependencies:
- dependency-name: peter-evans/create-pull-request
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-09 21:46:50 -05:00
github-actions[bot]
13d8dc095d
Assigned RUSTSEC-2024-0013 to libgit2-sys ( #1880 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-02-09 21:46:05 -05:00
Eric Huss
da4911ca94
Add advisory for libgit2-sys ( #1879 )
...
* Add advisory for libgit2-sys
* Fix function prefix.
* Remove empty affected table
2024-02-10 02:45:39 +00:00
github-actions[bot]
9afff95de4
Assigned RUSTSEC-2024-0011 to snow, RUSTSEC-2024-0012 to serde-json-wasm ( #1878 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-02-09 02:03:39 +00:00
Jake McGinty
514e599cbf
snow: Unauthenticated Nonce Increment ( #1866 )
2024-02-09 02:02:57 +00:00
Christoph Otter
f395a84350
Add serde-json-wasm stack-overflow ( #1867 )
2024-02-09 02:02:21 +00:00
github-actions[bot]
2bb64f5005
Assigned RUSTSEC-2023-0079 to pqc_kyber ( #1877 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-02-09 02:00:39 +00:00
Alexander Kjäll
ad9fb41032
Add advisory for the kyberslash timing attack ( #1872 )
...
* Add advisory for the kyberslash timing attack
* seems like rustsec doesn't support the cvss 3.1 'Temporal Score Metrics'
* fixed review feedback
* Mention the safe fork
---------
Co-authored-by: Alexander Kjäll <alexander.kjaell@schibsted.com >
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com >
2024-02-09 01:59:49 +00:00
github-actions[bot]
f48f2ed5e0
Assigned RUSTSEC-2024-0010 to svix ( #1876 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-02-06 17:57:48 +00:00
Aaron
d3d8d65101
Add svix signature verification issue ( #1875 )
2024-02-06 17:55:25 +00:00
Jacob Rothstein
1d2202ea2b
Add CVE alias for RUSTSEC-2024-000{8,9} ( #1869 )
2024-01-24 17:00:49 +00:00
Tony Arcieri
e4af460c5d
README.md: update maintained image ( #1868 )
...
It's now 2024
2024-01-24 05:49:54 -07:00
github-actions[bot]
7d1034dee2
Assigned RUSTSEC-2024-0008 to trillium-client, RUSTSEC-2024-0009 to trillium-http ( #1865 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-01-24 03:14:25 +00:00
Jacob Rothstein
de7a809f3e
Add advisories for trillium-http and trillium-client ( #1864 )
...
* Add GHSA-9f9p-cp3c-72jf
* add credit section
2024-01-24 03:13:27 +00:00
github-actions[bot]
7593ce7af2
Assigned RUSTSEC-2024-0007 to rust-i18n-support ( #1863 )
...
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com >
2024-01-23 07:45:36 -07:00
René Kijewski
b1db690d83
rust-i18n-support: Use-after-free when setting the locale ( #1855 )
2024-01-23 07:13:25 -07:00
dependabot[bot]
c88b5f38f2
Bump actions/cache from 3 to 4 ( #1862 )
...
Bumps [actions/cache](https://github.com/actions/cache ) from 3 to 4.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-22 08:08:15 -07:00
github-actions[bot]
fbc3b29aca
Assigned RUSTSEC-2024-0006 to shlex ( #1861 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-01-22 05:34:54 +00:00
comex
c90927bcc6
shlex: multiple issues involving quote API ( #1860 )
...
* Add `shlex` advisory
* Fix link
* Repoint URL to advisory
* Fix affected.functions syntax
---------
Co-authored-by: comex <comex@comex.local >
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com >
2024-01-22 05:33:45 +00:00
github-actions[bot]
7bfe993af3
Assigned RUSTSEC-2024-0005 to threadalone ( #1859 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-01-22 02:05:54 +00:00
Sergey "Shnatsel" Davidoff
412fc10e86
Unsound sending of non-Send types in threadalone, patched ( #1858 )
...
* Add advisory for threadalone
* Fix filename
2024-01-22 02:05:00 +00:00
github-actions[bot]
78ab2418dd
Assigned RUSTSEC-2024-0004 to cosmwasm ( #1857 )
...
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com >
2024-01-21 07:51:38 -07:00
Simon Warta
a623e80cfc
Mark crate cosmwasm as unmaintained ( #1856 )
2024-01-21 07:50:42 -07:00
github-actions[bot]
33acf3edda
Assigned RUSTSEC-2024-0003 to h2 ( #1853 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2024-01-17 21:03:44 +00:00