Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Audit finding: https://rustsec.org/advisories/RUSTSEC-2023-0081 #36616

Closed
brave-builds opened this issue Mar 7, 2024 · 6 comments · Fixed by brave/audit-config#43
Closed

Comments

@brave-builds
Copy link
Collaborator

Greetings human!

Bad news. Audit failed on nightly/v1.65.65 due to https://rustsec.org/advisories/RUSTSEC-2023-0081.

@rillian
Copy link

rillian commented Mar 7, 2024

Can be addressed with this patch, which also applies to our 0.3.1 version.

@bridiver
Copy link
Contributor

bridiver commented Mar 7, 2024

I'd prefer not to patch this, can we ignore this and wait for a bump to lol_html? This is only used by speedreader

@rillian
Copy link

rillian commented Mar 7, 2024

I don't think it's urgent. The main issue is being insensitive to any security issues found in the unmaintained library between ignoring the warning and actually bumping lol_html.

rillian added a commit to brave/audit-config that referenced this issue Mar 7, 2024
This crate is unmaintained. Ignore the warning until lol_html
(our only path to the dependency) publishes an update removing
it.

Resolves brave/brave-browser#36616
@brave-builds
Copy link
Collaborator Author

@brave-builds
Copy link
Collaborator Author

Audit failed on beta/v1.64.98 due to https://rustsec.org/advisories/RUSTSEC-2023-0081.

@brave-builds
Copy link
Collaborator Author

diracdeltas pushed a commit to brave/audit-config that referenced this issue Mar 8, 2024
This crate is unmaintained. Ignore the warning until lol_html
(our only path to the dependency) publishes an update removing
it.

Resolves brave/brave-browser#36616
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment