You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
chore: add RUSTSEC-2024-0436 to ignore list for cargo deny (#3526)
`paste` is a library that helps combine strings when building proc
macros. It is used in several datafusion crates as well as in our own
creates (we brought it over when we vendored bitpacking).
RUSTSEC-2024-0436 reports that paste is unmaintained
However, it appears the main reason is simply that `paste` is more or
less a "finished" library. It is one of the 200 most downloaded rust
libraries (it is somewhat ubiquitous when building proc macros) and it
seems likely that someone will step up and fix any security issues that
are detected.
This seems an acceptable risk to ignore this advisory.
0 commit comments