awslabs / tough

Rust libraries and tools for using and generating TUF repositories
191 stars 45 forks source link

Bump `cargo-deny` in Makefile #658

Closed jpculp closed 11 months ago

jpculp commented 11 months ago

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

jpculp commented 11 months ago

It looks like I need to wait for #655 to merge (since cargo-deny requires Rust 1.70+) or bump to 1.13.9 instead. Did anyone have opinions one way or the other? Hopefully folks upgraded to 1.71.1 to address CVE-2023-38497, but I could see someone hanging onto Rust 1.69 to avoid the new default "sparse" protocol in Cargo.

stmcginnis commented 11 months ago

655 now merged - I think this would be good to do.