mirror of
https://github.com/chenxiaolong/avbroot.git
synced 2026-07-03 14:05:11 +02:00
2c1d86cd96
Issue: #516 Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
69 lines
2.0 KiB
TOML
69 lines
2.0 KiB
TOML
[advisories]
|
|
version = 2
|
|
yanked = "deny"
|
|
ignore = [
|
|
# https://rustsec.org/advisories/RUSTSEC-2023-0071
|
|
#
|
|
# This is a side-channel vulnerability where secrets can be leaked to an
|
|
# attacker that is able to measure the timing of a large number of RSA
|
|
# operations. As of 2023-12-03, there is no released version of the rsa
|
|
# crate that contains a fix.
|
|
#
|
|
# For avbroot specifically, this vulnerability is not too critical for a
|
|
# couple reasons:
|
|
#
|
|
# 1. avbroot performs RSA signing only at the end of lengthy processes
|
|
# that involve a lot of disk I/O. It's very expensive to run avbroot
|
|
# the millions of times needed to capture a sufficient amount of timing
|
|
# data.
|
|
# 2. During a single run of avbroot, it will only perform RSA signing a
|
|
# handful of times. To get sufficient measurements, the attacker would
|
|
# need to rerun avbroot. If they are able to rerun avbroot, then they
|
|
# are also able to just read and steal the private key directly.
|
|
#
|
|
# avbroot has no network capabilities, so this is not inherently remotely
|
|
# exploitable.
|
|
"RUSTSEC-2023-0071",
|
|
]
|
|
|
|
[licenses]
|
|
version = 2
|
|
include-dev = true
|
|
allow = [
|
|
"Apache-2.0",
|
|
"Apache-2.0 WITH LLVM-exception",
|
|
"BSD-3-Clause",
|
|
"bzip2-1.0.6",
|
|
"GPL-3.0-only",
|
|
"ISC",
|
|
"MIT",
|
|
"Unicode-3.0",
|
|
"Zlib",
|
|
]
|
|
|
|
[bans]
|
|
multiple-versions = "warn"
|
|
multiple-versions-include-dev = true
|
|
deny = [
|
|
# https://github.com/serde-rs/serde/issues/2538
|
|
{ name = "serde_derive", version = ">=1.0.172,<1.0.184" },
|
|
]
|
|
|
|
[bans.build]
|
|
executables = "deny"
|
|
include-dependencies = true
|
|
include-workspace = true
|
|
bypass = [
|
|
# Copies of unmodified crashwrangler objects for old macOS versions.
|
|
{ name = "honggfuzz", allow-globs = ["honggfuzz/third_party/mac/CrashReport_*.o"] },
|
|
# Only used in tests.
|
|
{ name = "libloading", allow-globs = ["tests/nagisa*.dll"] },
|
|
]
|
|
|
|
[sources]
|
|
unknown-registry = "deny"
|
|
unknown-git = "deny"
|
|
allow-git = [
|
|
"https://github.com/chenxiaolong/system-properties",
|
|
]
|