Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Idea: optional warning when --ignore flags are no longer necessary #1180

Open
Shnatsel opened this issue May 2, 2024 · 0 comments
Open

Idea: optional warning when --ignore flags are no longer necessary #1180

Shnatsel opened this issue May 2, 2024 · 0 comments
Labels
cargo-audit crate Issues relating to the `cargo-audit` crate enhancement

Comments

@Shnatsel
Copy link
Member

Shnatsel commented May 2, 2024

Moving from rust-secure-code/cargo-auditable#140

In my crate CI, I have some --ignore flags for vulnerabilities that do not apply to dependencies as used by my crates (e.g., RUSTSEC-2020-0159 in crates that never end up calling localtime_r). It would be nice to automatically know when I can remove them because versions have crept up over time. Perhaps an "unused ignore flag value" warning?

cc @mathstuf

@Shnatsel Shnatsel added enhancement cargo-audit crate Issues relating to the `cargo-audit` crate labels May 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cargo-audit crate Issues relating to the `cargo-audit` crate enhancement
Projects
None yet
Development

No branches or pull requests

1 participant