You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The docs have no guidance on how to flag dependencies as needing fixes/replacement, but not stop-the-release urgently. A violation with any of the built-in criteria would be too disruptive.
How to flag low-severity vulnerabilities or unsoundness?
I'm not sure how to name custom criteria for use with with violation. They're negated, so an unmaintained crate would be a violation and maintained criteria?
Maybe cargo-vet could have a dedicated support for warnings?
The text was updated successfully, but these errors were encountered:
The docs have no guidance on how to flag dependencies as needing fixes/replacement, but not stop-the-release urgently. A violation with any of the built-in criteria would be too disruptive.
How to flag low-severity vulnerabilities or unsoundness?
I'm not sure how to name custom criteria for use with with
violation
. They're negated, so an unmaintained crate would be aviolation
andmaintained
criteria?Maybe cargo-vet could have a dedicated support for warnings?
The text was updated successfully, but these errors were encountered: