Skip to content

sec: ignore RUSTSEC-2026-0097 for now#2245

Merged
svix-jbrown merged 1 commit intomainfrom
jbrown/rand-0.10
Apr 13, 2026
Merged

sec: ignore RUSTSEC-2026-0097 for now#2245
svix-jbrown merged 1 commit intomainfrom
jbrown/rand-0.10

Conversation

@svix-jbrown
Copy link
Copy Markdown
Contributor

RUSTSEC-2026-0097 is a somewhat subtle bug in rand; there isn't a fix available for 0.8.x., but several of our dependencies (including sqlx and num-bigint) don't support 0.9/0.10 yet.

We don't configure a logger that uses rand::thread_rng anyway.

@svix-jbrown svix-jbrown requested a review from a team as a code owner April 13, 2026 21:31
@svix-jbrown svix-jbrown merged commit 52291e0 into main Apr 13, 2026
11 checks passed
@svix-jbrown svix-jbrown deleted the jbrown/rand-0.10 branch April 13, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants