Skip to content

chore(deps): bump config from 0.13.4 to 0.14.1#818

Merged
Xynnn007 merged 1 commit into
confidential-containers:mainfrom
mythi:deps-config
Nov 24, 2024
Merged

chore(deps): bump config from 0.13.4 to 0.14.1#818
Xynnn007 merged 1 commit into
confidential-containers:mainfrom
mythi:deps-config

Conversation

@mythi
Copy link
Copy Markdown
Contributor

@mythi mythi commented Nov 22, 2024

For some reason, dependabot had missed this useful update. v0.14.x series gets more care and also updates its dependencies to drop unmaintained yaml-rust.

makes cargo audit happier:

Crate: yaml-rust
Version: 0.4.5
Warning: unmaintained
Title: yaml-rust is unmaintained.
Date: 2024-03-20
ID: RUSTSEC-2024-0320
URL: https://rustsec.org/advisories/RUSTSEC-2024-0320

@mythi mythi requested a review from a team as a code owner November 22, 2024 08:12
Copy link
Copy Markdown
Member

@Xynnn007 Xynnn007 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm. Let's see if ci is good

@mythi
Copy link
Copy Markdown
Contributor Author

mythi commented Nov 22, 2024

looks like the errors were network glitches or similar. the failing tests are passing OK locally so I just re-pushed

@Xynnn007
Copy link
Copy Markdown
Member

let me make a pr to fix the error. Might be related to confidential-containers/trustee#553

@Xynnn007
Copy link
Copy Markdown
Member

see #819

For some reason, dependabot had missed this useful update. v0.14.x
series gets more care and also updates its dependencies to drop
unmaintained yaml-rust.

makes cargo audit happier:

Crate:     yaml-rust
Version:   0.4.5
Warning:   unmaintained
Title:     yaml-rust is unmaintained.
Date:      2024-03-20
ID:        RUSTSEC-2024-0320
URL:       https://rustsec.org/advisories/RUSTSEC-2024-0320

Signed-off-by: Mikko Ylinen <mikko.ylinen@intel.com>
@Xynnn007 Xynnn007 merged commit 9d75270 into confidential-containers:main Nov 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants