2026-08-12 23:30:30 +05:30
|
|
|
# cargo-audit configuration for nxtgauge-backend-rust
|
|
|
|
|
# https://github.com/rustsec/rustsec/tree/main/cargo-audit#configuration
|
|
|
|
|
#
|
|
|
|
|
# Keep this in sync with the [advisories].ignore list in deny.toml — cargo-deny
|
|
|
|
|
# is the gate that actually runs in CI/policy checks, but the live-server
|
|
|
|
|
# runbook also runs `cargo audit` directly, so both need to agree on
|
|
|
|
|
# accepted risk to both exit 0.
|
|
|
|
|
|
2026-05-31 18:25:38 +05:30
|
|
|
[advisories]
|
|
|
|
|
ignore = [
|
2026-08-12 23:30:30 +05:30
|
|
|
# RUSTSEC-2023-0071 - rsa: Marvin Attack timing side-channel — no upstream fix available.
|
|
|
|
|
# Impact: potential RSA key recovery via timing. Low risk: we use RSA only for JWT
|
|
|
|
|
# verification (public-key ops), not for decryption. Acknowledged (see deny.toml).
|
|
|
|
|
"RUSTSEC-2023-0071",
|
|
|
|
|
# RUSTSEC-2025-0141 - bincode: unmaintained (not a vulnerability, just no active maintainer).
|
|
|
|
|
# bincode is used transitively; no replacement available in our dep tree.
|
|
|
|
|
"RUSTSEC-2025-0141",
|
|
|
|
|
# RUSTSEC-2026-0235 - rkyv: out-of-bounds read validating Rc/Arc in archives.
|
|
|
|
|
# Pulled in only as an optional dependency of rust_decimal (apps/payments); we use
|
|
|
|
|
# rust_decimal with `features = ["db-tokio-postgres"]` only — the "rkyv" feature is
|
|
|
|
|
# never enabled, so this crate is never actually compiled into our binaries.
|
|
|
|
|
# Confirmed via `cargo tree -p payments -e features | grep rkyv` (empty). Cargo.lock
|
|
|
|
|
# still lists it because lock files record the full possible graph, not just the
|
|
|
|
|
# feature-activated one — that's also why cargo-deny (which resolves features) never
|
|
|
|
|
# flags it while cargo-audit (which scans the lockfile as-is) does. Re-check this
|
|
|
|
|
# exemption if rust_decimal's default features ever change.
|
|
|
|
|
"RUSTSEC-2026-0235",
|
|
|
|
|
|
|
|
|
|
# ── False positives: crate-name collisions with our own workspace crates ──────
|
|
|
|
|
# cargo-audit matches by (name, version) against Cargo.lock and does not check
|
|
|
|
|
# whether the entry is a local path dependency vs a crates.io registry crate.
|
|
|
|
|
# Our internal workspace crates crates/cache ("cache" 0.1.0) and apps/users
|
|
|
|
|
# ("users" 0.1.0) happen to share both name and version with unrelated,
|
|
|
|
|
# long-abandoned crates.io packages that these advisories target. cargo-deny
|
|
|
|
|
# (which resolves the real dependency graph, not just name+version matching)
|
|
|
|
|
# correctly does not flag any of these — confirmed via
|
|
|
|
|
# `cargo deny check advisories` showing none of these IDs. Verify via
|
|
|
|
|
# `grep -A3 '^name = "cache"$' Cargo.lock` (no `source = "registry+..."` line)
|
|
|
|
|
# before ever removing these.
|
|
|
|
|
"RUSTSEC-2020-0128", # "cache" — Cache<K> Send/Sync soundness (unrelated crates.io crate)
|
|
|
|
|
"RUSTSEC-2021-0006", # "cache" — exposes internal raw pointer (unrelated crates.io crate)
|
|
|
|
|
"RUSTSEC-2023-0040", # "users" — unmaintained (unrelated crates.io crate)
|
|
|
|
|
"RUSTSEC-2023-0059", # "users" — unaligned pointer read (unrelated crates.io crate)
|
2026-05-31 18:25:38 +05:30
|
|
|
]
|