-
Notifications
You must be signed in to change notification settings - Fork 10
Open
Description
Describe the bug
cargo-audit reports an upstream vulnerability
Crate: ansi_term
Version: 0.12.1
Warning: unmaintained
Title: ansi_term is Unmaintained
Date: 2021-08-18
ID: RUSTSEC-2021-0139
URL: https://rustsec.org/advisories/RUSTSEC-2021-0139
Dependency tree:
ansi_term 0.12.1
└── clap 2.34.0
└── structopt 0.3.26
└── cargo_atelier 0.2.7
To Reproduce
install cargo-auditable and cargo-audit and run as described here https://github.com/rust-secure-code/cargo-auditable
Expected behavior
no warnings
Screenshots/Logs
see above
Environment (please complete the following information):
- Rust Version: 1.64
- Atelier crates: atelier_test 0.1.3
- Client code: n/a
Additional context
Updating to latest structopt (0.3.26) does not fix this. structopt is in maintenance mode and has been integrated into clap. Fixing this requires replacing the structopt dependency in cargo-atelier/src/command_line.rs to clap v4.
Metadata
Metadata
Assignees
Labels
No labels