Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Ignore RustSec warning.
Background
We get a non-critical warning when running
cargo audit
: RUSTSEC-2021-0139.When running
cargo tree -i -p=ansi_term
we can see thatansi_term
is a dependency ofdylint
andtracing-subscriber
v0.2. Whiletracing-subscriber
v0.3 doesn't depend uponansi_term
, we can't easily upgrade to that version as several of our dependencies do not support v0.3. Also,dylint
's latest version still depends uponansi_term
.Given that the RustSec report doesn't suggest any concrete problems with
ansi_term
and how difficult it will be to move away from this dependency, I have just ignored this warning in CI.We also have a further audit warning about v0.1.29 of
jobserver
being yanked, so I have updated that dependency.Changes
.cargo/audit.toml
file.Testing
CI and ran
cargo audit
locally.Related Issues
Closes #914.