diff --git a/.github/workflows/assign-ids.yml b/.github/workflows/assign-ids.yml index a8c45e198..5b8b860e1 100644 --- a/.github/workflows/assign-ids.yml +++ b/.github/workflows/assign-ids.yml @@ -23,11 +23,11 @@ jobs: uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 with: path: ~/.cargo/bin - key: rustsec-admin-4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + key: rustsec-admin-7ed6bee1571768e528a6631400d3b51f37463b29 - name: Install rustsec-admin if: steps.admin-cache.outputs.cache-hit != 'true' - run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 7ed6bee1571768e528a6631400d3b51f37463b29 - name: Assign IDs id: assign diff --git a/.github/workflows/export-osv.yml b/.github/workflows/export-osv.yml index ab4422c13..8343923f0 100644 --- a/.github/workflows/export-osv.yml +++ b/.github/workflows/export-osv.yml @@ -21,11 +21,11 @@ jobs: id: admin-cache with: path: ~/.cargo/bin - key: rustsec-admin-4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + key: rustsec-admin-7ed6bee1571768e528a6631400d3b51f37463b29 - name: Install rustsec-admin if: steps.admin-cache.outputs.cache-hit != 'true' - run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 7ed6bee1571768e528a6631400d3b51f37463b29 - run: | mkdir -p crates diff --git a/.github/workflows/publish-web.yml b/.github/workflows/publish-web.yml index c2643c523..897137c63 100644 --- a/.github/workflows/publish-web.yml +++ b/.github/workflows/publish-web.yml @@ -21,11 +21,11 @@ jobs: id: admin-cache with: path: ~/.cargo/bin - key: rustsec-admin-4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + key: rustsec-admin-7ed6bee1571768e528a6631400d3b51f37463b29 - name: Install rustsec-admin if: steps.admin-cache.outputs.cache-hit != 'true' - run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 7ed6bee1571768e528a6631400d3b51f37463b29 - run: | rustsec-admin web . diff --git a/.github/workflows/sync-ids.yml b/.github/workflows/sync-ids.yml index 8e37edf99..906a8c82f 100644 --- a/.github/workflows/sync-ids.yml +++ b/.github/workflows/sync-ids.yml @@ -25,11 +25,11 @@ jobs: uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 with: path: ~/.cargo/bin - key: rustsec-admin-4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + key: rustsec-admin-7ed6bee1571768e528a6631400d3b51f37463b29 - name: Install rustsec-admin if: steps.admin-cache.outputs.cache-hit != 'true' - run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 7ed6bee1571768e528a6631400d3b51f37463b29 - name: Synchronize IDs id: sync_ids diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index f22ce4fb0..8edd9a4e6 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -21,11 +21,11 @@ jobs: uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 with: path: ~/.cargo/bin - key: rustsec-admin-4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + key: rustsec-admin-7ed6bee1571768e528a6631400d3b51f37463b29 - name: Install rustsec-admin if: steps.admin-cache.outputs.cache-hit != 'true' - run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 4f949d61d9ed2ef59f8c4448b5ab96e6eef0d6ed + run: cargo install --git https://github.com/rustsec/rustsec rustsec-admin --rev 7ed6bee1571768e528a6631400d3b51f37463b29 - name: Lint advisories run: rustsec-admin lint --skip-namecheck rustdecimal,vec-const diff --git a/crates/rustdecimal/RUSTSEC-2022-0042.md b/crates/rustdecimal/RUSTSEC-2022-0042.md index d0d98822d..b8af7fff7 100644 --- a/crates/rustdecimal/RUSTSEC-2022-0042.md +++ b/crates/rustdecimal/RUSTSEC-2022-0042.md @@ -7,6 +7,8 @@ url = "https://groups.google.com/g/rustlang-security-announcements/c/5DVtC8pgJLw categories = ["code-execution"] keywords = ["typosquatting"] aliases = ["GHSA-7pwq-f4pq-78gm", "MAL-2022-1"] +expect-deleted = true + [versions] patched = [] ``` @@ -63,4 +65,4 @@ malicious crate in [this GitHub issue][1]. [1]: https://github.com/paupino/rust-decimal/issues/514#issuecomment-1115408888 [2]: https://crates.io/crates/rust_decimal [3]: https://www.rust-lang.org/policies/security -[4]: https://github.com/safinaskar +[4]: https://github.com/safinaskar diff --git a/crates/vec-const/RUSTSEC-2021-0082.md b/crates/vec-const/RUSTSEC-2021-0082.md index 904c69e42..40fe1fd03 100644 --- a/crates/vec-const/RUSTSEC-2021-0082.md +++ b/crates/vec-const/RUSTSEC-2021-0082.md @@ -8,6 +8,7 @@ categories = ["memory-corruption"] keywords = ["memory-safety"] informational = "unsound" aliases = ["CVE-2021-45680", "GHSA-jmwx-r3gq-qq3p", "GHSA-x76r-966h-5qv9"] +expect-deleted = true [versions] patched = [">= 2.0.0"]