Skip to content

Commit 91ea251

Browse files
authored
ignore new audit warnings (#142)
1 parent 05b6814 commit 91ea251

1 file changed

Lines changed: 12 additions & 0 deletions

File tree

.cargo/audit.toml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,4 +27,16 @@ ignore = [
2727
# logger calls `rand::rng()` during reseeding. Our 0.8.5 (transitive via alloy-consensus)
2828
# has neither feature enabled; our 0.9.4 is already patched.
2929
"RUSTSEC-2026-0097",
30+
31+
# `hickory-proto` 0.25.2 NSEC3 closest-encloser proof validation unbounded loop on cross-zone
32+
# responses. No fixed upgrade is available. Transitive dep via reth's `reth-dns-discovery` ->
33+
# `hickory-resolver`. node-components does not perform DNSSEC validation, so this code path is
34+
# unused.
35+
"RUSTSEC-2026-0118",
36+
37+
# `hickory-proto` 0.25.2 O(n²) name-compression CPU exhaustion during message encoding. Fix is
38+
# in 0.26.1, but `hickory-resolver` 0.25.2 (pinned by reth's `reth-dns-discovery`) requires
39+
# `hickory-proto ^0.25`, so we can't upgrade until reth bumps. node-components does not encode
40+
# DNS messages.
41+
"RUSTSEC-2026-0119",
3042
]

0 commit comments

Comments
 (0)