Skip to content

Remove the stale RUSTSEC-2025-0055 audit ignore - #452

Merged
jadamcrain merged 1 commit into
mainfrom
remove-stale-audit-ignore
Oct 9, 2026
Merged

jadamcrain merged 1 commit into
mainfrom
remove-stale-audit-ignore

Conversation

@jadamcrain

Copy link
Copy Markdown
Member

.cargo/audit.toml only ignored RUSTSEC-2025-0055 (tracing-subscriber ANSI escape injection). That advisory is fixed in tracing-subscriber 0.3.20 and Cargo.lock has 0.3.23, so the ignore no longer has any effect: cargo audit 0.22.1 on main's lockfile without the file reports no vulnerabilities, and OSV-Scanner (#451) never reports it either.

Removing the file also makes dnp3's security setup identical to rodbus's (stepfunc/rodbus#202), which has no audit ignores. The workflow's path trigger for .cargo/audit.toml stays, for any future ignore.

The advisory (tracing-subscriber ANSI escape injection) is fixed in
tracing-subscriber 0.3.20, and Cargo.lock has 0.3.23, so cargo audit no
longer reports it and the ignore had no effect. It was the only entry in
.cargo/audit.toml, which also makes the security setup match rodbus's.
@jadamcrain
jadamcrain merged commit 1e2dc8c into main Oct 9, 2026
65 of 66 checks passed
@jadamcrain
jadamcrain deleted the remove-stale-audit-ignore branch October 9, 2026 23:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant