File tree 2 files changed +23
-1
lines changed
2 files changed +23
-1
lines changed Original file line number Diff line number Diff line change @@ -9,6 +9,27 @@ targets = [
9
9
10
10
[advisories ]
11
11
yanked = " deny"
12
+ ignore = [
13
+ # https://rustsec.org/advisories/RUSTSEC-2023-0071
14
+ # "rsa" crate: Marvin Attack: potential key recovery through timing sidechannel
15
+ #
16
+ # No patch is yet available, however work is underway to migrate to a fully constant-time implementation
17
+ # So we need to accept this, as of SDP 24.11 we are not using the rsa crate to create certificates used in production
18
+ # setups.
19
+ #
20
+ # TODO: Remove after https://github.com/RustCrypto/RSA/pull/394 is merged
21
+ " RUSTSEC-2023-0071" ,
22
+
23
+ # https://rustsec.org/advisories/RUSTSEC-2024-0384
24
+ # "instant" is unmaintained
25
+ #
26
+ # The upstream "kube" crate also silenced this in https://github.com/kube-rs/kube/commit/4f1e889f265da8f19f03f60683569cae1a154fda
27
+ # They/we are actively working on migrating kube from backoff to backon, which removes the transitive dependency on
28
+ # instant, in https://github.com/kube-rs/kube/pull/1652.
29
+ #
30
+ # TODO: Remove after https://github.com/kube-rs/kube/pull/1652 is merged
31
+ " RUSTSEC-2024-0384" ,
32
+ ]
12
33
13
34
[bans ]
14
35
multiple-versions = " allow"
@@ -26,6 +47,7 @@ allow = [
26
47
" LicenseRef-webpki" ,
27
48
" MIT" ,
28
49
" MPL-2.0" ,
50
+ " OpenSSL" , # Needed for the ring and/or aws-lc-sys crate. See https://github.com/stackabletech/operator-templating/pull/464 for details
29
51
" Unicode-3.0" ,
30
52
" Unicode-DFS-2016" ,
31
53
" Zlib" ,
Original file line number Diff line number Diff line change 21
21
if ! command -v jinja2 & > /dev/null
22
22
then
23
23
echo " jinja2 could not be found. Use 'pip install jinja2-cli' to install it."
24
- exit
24
+ exit 1
25
25
fi
26
26
27
27
# Check if templating vars file exists
You can’t perform that action at this time.
0 commit comments