Skip to content

Yanked version ignored too much #154

@cecton

Description

@cecton

Related to: rust-disk-partition-management/gptman#82 (comment)

We noticed that yanked dependencies do not seem to be reported at all. They're not necessarily vulnerabilities but they should be reported at least as outdated.

This can be observed in commit rust-disk-partition-management/gptman@d7ca717

It is important to note that:

  1. crossbeam-utils is not a direct dependency of the project
  2. it's only pulled for the binary of this crate and not the library

Possibly related to #109

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions