generated from amazon-archives/__template_Apache-2.0
-
Notifications
You must be signed in to change notification settings - Fork 18
Open
Description
aws-nitro-enclaves-image-format currently still depends on clap 3.2.x, which pulls in the unmaintained atty crate as a transitive dependency. This gets flagged by dependabot on downstream projects.
See https://rustsec.org/advisories/RUSTSEC-2024-0375 and https://rustsec.org/advisories/RUSTSEC-2021-0145 for context.
To resolve this, a switch to a newer clap 4.x branch is needed, which drops atty as a dependency. Dependabot created the PR #37 , but it seems that API changes in clap need to be resolved by the maintainers.
Other AWS nitro enclave crates resolved this already, see for example aws/aws-nitro-enclaves-cli@6245dbc .
Metadata
Metadata
Assignees
Labels
No labels