From 28a7afc89228abb97207a5c52a0d1fb5966a573e Mon Sep 17 00:00:00 2001 From: Sebastian Thiel Date: Mon, 22 Apr 2024 08:56:00 +0200 Subject: [PATCH] Upgrade lock-file to latest version to avoid `cargo-deny` failure --- Cargo.lock | 24 ++++++++++++------------ deny.toml | 5 ++++- 2 files changed, 16 insertions(+), 13 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index acb053ba08d..93ee941713c 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -802,24 +802,24 @@ dependencies = [ [[package]] name = "curl" -version = "0.4.44" +version = "0.4.46" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "509bd11746c7ac09ebd19f0b17782eae80aadee26237658a6b4808afb5c11a22" +checksum = "1e2161dd6eba090ff1594084e95fd67aeccf04382ffea77999ea94ed42ec67b6" dependencies = [ "curl-sys", "libc", "openssl-probe", "openssl-sys", "schannel", - "socket2 0.4.10", - "winapi", + "socket2 0.5.5", + "windows-sys 0.52.0", ] [[package]] name = "curl-sys" -version = "0.4.70+curl-8.5.0" +version = "0.4.72+curl-8.6.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "3c0333d8849afe78a4c8102a429a446bfdd055832af071945520e835ae2d841e" +checksum = "29cbdc8314c447d11e8fd156dcdd031d9e02a7a976163e396b548c03153bc9ea" dependencies = [ "cc", "libc", @@ -828,7 +828,7 @@ dependencies = [ "pkg-config", "rustls-ffi", "vcpkg", - "windows-sys 0.48.0", + "windows-sys 0.52.0", ] [[package]] @@ -3042,7 +3042,7 @@ dependencies = [ "http", "hyper", "hyper-util", - "rustls 0.22.2", + "rustls 0.22.4", "rustls-pki-types", "tokio", "tokio-rustls", @@ -3964,7 +3964,7 @@ dependencies = [ "once_cell", "percent-encoding", "pin-project-lite", - "rustls 0.22.2", + "rustls 0.22.4", "rustls-pemfile 1.0.4", "rustls-pki-types", "serde", @@ -4074,9 +4074,9 @@ dependencies = [ [[package]] name = "rustls" -version = "0.22.2" +version = "0.22.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e87c9956bd9807afa1f77e0f7594af32566e830e088a5576d27c5b6f30f49d41" +checksum = "bf4ef73721ac7bcd79b2b315da7779d8fc09718c6b3d2d1b2d94850eb8c18432" dependencies = [ "log", "ring 0.17.7", @@ -4674,7 +4674,7 @@ version = "0.25.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "775e0c0f0adb3a2f22a00c4745d728b479985fc15ee7ca6a2608388c5569860f" dependencies = [ - "rustls 0.22.2", + "rustls 0.22.4", "rustls-pki-types", "tokio", ] diff --git a/deny.toml b/deny.toml index ddddea8f5f6..1e8ed3f49e0 100644 --- a/deny.toml +++ b/deny.toml @@ -22,7 +22,10 @@ yanked = "warn" # 2019-12-17 there are no security notice advisories in # https://github.com/rustsec/advisory-db notice = "warn" -ignore = [] +ignore = [ + # this is `rustls@0.20.9` coming in with `curl`, which doesn't have an update yet. It's only active optionally, not by default. + "RUSTSEC-2024-0336", +]