Skip to content

Commit 2d31411

Browse files
committed
security(cargo): vet our own package
1 parent 6662549 commit 2d31411

File tree

3 files changed

+10
-4
lines changed

3 files changed

+10
-4
lines changed

supply-chain/audits.toml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,12 @@ notes = """
3131
- use of Box to store global data
3232
"""
3333

34+
[[audits.wasm-component-trampoline]]
35+
who = "bill fumerola <bill@andyl.com>"
36+
criteria = "safe-to-deploy"
37+
version = "0.1.1"
38+
notes = "internal audit, no use of unsafe, filesystem access limited to integration tests"
39+
3440
[[trusted.anyhow]]
3541
criteria = "safe-to-deploy"
3642
user-id = 3618 # David Tolnay (dtolnay)

supply-chain/config.toml

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,3 @@ criteria = "safe-to-deploy"
7575
[[exemptions.trait-variant]]
7676
version = "0.1.2"
7777
criteria = "safe-to-deploy"
78-
79-
[[exemptions.wasm-component-trampoline]]
80-
version = "0.1.2-pre"
81-
criteria = "safe-to-deploy"

supply-chain/imports.lock

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11

22
# cargo-vet imports lock
33

4+
[[unpublished.wasm-component-trampoline]]
5+
version = "0.1.2-pre"
6+
audited_as = "0.1.1"
7+
48
[[publisher.anyhow]]
59
version = "1.0.98"
610
when = "2025-04-14"

0 commit comments

Comments
 (0)