Skip to content

chore(deps): track RUSTSEC-2024-0436 with review-by date - #97

Open
DeryFerd wants to merge 4 commits into
Growth-Circle:mainfrom
DeryFerd:chore/track-paste-advisory
Open

DeryFerd wants to merge 4 commits into
Growth-Circle:mainfrom
DeryFerd:chore/track-paste-advisory

Conversation

@DeryFerd

Copy link
Copy Markdown
Contributor

Problem

The deny.toml file ignores RUSTSEC-2024-0436 (a vulnerability in the paste crate) with a generic reason:

ignore = [
    { id = "RUSTSEC-2024-0436", reason = "paste is a transitive dep through egui/accesskit; awaiting upstream migration" },
]

The problem with leaving it like this is that ignored advisories have a tendency to become permanent. Six months from now, nobody on the team will remember why it was ignored, whether it's still relevant, or whether paste has been replaced by a fork with a fix. The advisory database doesn't stop tracking it just because it's in the ignore list — if a CVE gets assigned later, the team should know about it.

Solution

Add a review-by date (3 months out) and a brief risk assessment to the reason field:

{ id = "RUSTSEC-2024-0436", reason = "paste is a transitive dep through egui/accesskit; awaiting upstream migration (review-by: 2026-09-27; low direct risk — paste only used in accesskit/egui build macros)" },

This does three things:

  1. Bakes in a deadline — review-by: 2026-09-27 means someone needs to re-evaluate this entry by that date. If paste has been patched or replaced upstream, the ignore can be removed.
  2. Documents severity — low direct risk makes it clear that this isn't a runtime vulnerability. paste is only pulled in as a build-time dependency through egui's accesskit integration, not in any runtime code path.
  3. Keeps the context in one place — no need to dig through commit messages or issues to understand why this advisory was ignored.

Affected Files

  • deny.toml — updated ignore entry reason

Risk

None. Documentation-only change. The ignore entry remains functionally identical — cargo deny still suppresses the advisory, the build still passes, and the runtime behavior doesn't change. The only difference is that six months from now, someone reading this won't have to guess whether it's still safe.

Add a review-by date and assessment to the ignored paste crate
advisory so the deferral is time-bounded and auditable.
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant