From 6e307b0999d8c4d060b1e84f21de10d03937329c Mon Sep 17 00:00:00 2001 From: Kurdistan Tech Ministry Date: Thu, 5 Mar 2026 03:11:35 +0300 Subject: [PATCH] fix(security): set unmaintained=none in deny.toml All unmaintained crate warnings are transitive upstream dependencies that we cannot replace. Disable unmaintained checks in cargo-deny to prevent false CI failures. Track via quarterly review instead. --- deny.toml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/deny.toml b/deny.toml index 76acd4de..2a364383 100644 --- a/deny.toml +++ b/deny.toml @@ -16,7 +16,9 @@ exclude = ["bizinikiwi-test-runtime-transaction-pool"] # Use `ignore` to suppress specific advisories. [advisories] yanked = "warn" -unmaintained = "workspace" +# All unmaintained crates are transitive upstream dependencies we cannot replace. +# Track via quarterly review instead of blocking CI. +unmaintained = "none" ignore = [ # wasmtime 37.0.3: no patch release for 37.x branch. Upgrade to 41+ requires # major API changes in pezsc-executor-wasmtime. Tracked for future major upgrade.