Skip to content

Consider switching to clap 4.x #44

@cr-tk

Description

@cr-tk

aws-nitro-enclaves-image-format currently still depends on clap 3.2.x, which pulls in the unmaintained atty crate as a transitive dependency. This gets flagged by dependabot on downstream projects.
See https://rustsec.org/advisories/RUSTSEC-2024-0375 and https://rustsec.org/advisories/RUSTSEC-2021-0145 for context.

To resolve this, a switch to a newer clap 4.x branch is needed, which drops atty as a dependency. Dependabot created the PR #37 , but it seems that API changes in clap need to be resolved by the maintainers.

Other AWS nitro enclave crates resolved this already, see for example aws/aws-nitro-enclaves-cli@6245dbc .

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions