Ignore dependabot security alert

Open
#127 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
25/100
Issue type
Documentation
Clarity
Needs clarification
Activity status
Stale
Tech stack
rust
Domain
security

Research direction

Open the linked Dependabot alert and inspect how serde_cbor is used in the repository's tests. Confirm whether it is absent from production code and document the review outcome; the issue is done when the security concern has a clear, recorded resolution.

Written by the indexing model from the issue text.

Description

https://github.com/ElementsProject/rust-elements/security/dependabot/1 was dismissed by me with the note "Severe for this project". serde_cbor was only used in tests. serde_cbor was only used in test.

Opening an issue for people to double check

Dominant language
Rust
Stars
57
Forks
40
Avg merge
11h 58m
Merged PRs (30d)
1

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from ElementsProject/rust-elements

All issues in ElementsProject/rust-elements

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.