From 03bc5b16de81c109d0b50d637f5b3e79d5b9adab Mon Sep 17 00:00:00 2001 From: Andrew Briscoe Date: Sun, 26 Jul 2026 10:08:41 -0600 Subject: [PATCH] chore(deps): document dev-only FluxBench advisories --- deny.toml | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/deny.toml b/deny.toml index 70858bf..d3ab625 100644 --- a/deny.toml +++ b/deny.toml @@ -26,8 +26,14 @@ targets = [ version = 2 yanked = "deny" ignore = [ - # Add advisory IDs here with a comment explaining the exception, e.g. - # "RUSTSEC-YYYY-NNNN", # only triggers on a code path we don't use; see #123 + # FluxBench 0.1.3 is the latest release and pulls fxhash only through its + # dev-only CLI/reporting stack. It is absent from PageDB's normal/build + # graph; no maintained fxhash release or FluxBench upgrade is available. + "RUSTSEC-2025-0057", + # Same boundary as above: number_prefix is reachable only through + # FluxBench -> indicatif in the dev-only benchmark CLI. Consumers never + # resolve it, and the advisory has no safe upgrade. + "RUSTSEC-2025-0119", ] # ────────────────────────────────────────────────────────────────────────