-
Notifications
You must be signed in to change notification settings - Fork 4
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
chore(audit): add audit.toml file & downgrade lockfile to v3
Signed-off-by: Anton Engelhardt <[email protected]>
- Loading branch information
1 parent
63ba0bb
commit db62b40
Showing
2 changed files
with
31 additions
and
1 deletion.
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,30 @@ | ||
# All of the options which can be passed via CLI arguments can also be | ||
# permanently specified in this file. | ||
|
||
[advisories] | ||
ignore = ["RUSTSEC-2023-0071"] # advisory IDs to ignore e.g. ["RUSTSEC-2019-0001", ...] | ||
informational_warnings = ["unmaintained"] # warn for categories of informational advisories | ||
severity_threshold = "low" # CVSS severity ("none", "low", "medium", "high", "critical") | ||
|
||
# Advisory Database Configuration | ||
[database] | ||
path = "~/.cargo/advisory-db" # Path where advisory git repo will be cloned | ||
url = "https://github.com/RustSec/advisory-db.git" # URL to git repo | ||
fetch = true # Perform a `git fetch` before auditing (default: true) | ||
stale = false # Allow stale advisory DB (i.e. no commits for 90 days, default: false) | ||
|
||
# Output Configuration | ||
[output] | ||
deny = ["unmaintained"] # exit on error if unmaintained dependencies are found | ||
format = "terminal" # "terminal" (human readable report) or "json" | ||
quiet = false # Only print information on error | ||
show_tree = true # Show inverse dependency trees along with advisories (default: true) | ||
|
||
# Target Configuration | ||
[target] | ||
arch = ["wasm32-wasi"] # Ignore advisories for CPU architectures other than these | ||
os = ["wasi"] # Ignore advisories for operating systems other than these | ||
|
||
[yanked] | ||
enabled = true # Warn for yanked crates in Cargo.lock (default: true) | ||
update_index = true # Auto-update the crates.io index (default: true) |