Skip to content

Clam 2436 no clap no atty 1.0.4#1035

Merged
val-ms merged 2 commits intoCisco-Talos:dev/1.0.4from
val-ms:CLAM-2436-no-clap-no-atty-1.0.4
Oct 23, 2023
Merged

Clam 2436 no clap no atty 1.0.4#1035
val-ms merged 2 commits intoCisco-Talos:dev/1.0.4from
val-ms:CLAM-2436-no-clap-no-atty-1.0.4

Conversation

@val-ms
Copy link
Contributor

@val-ms val-ms commented Sep 26, 2023

Backport of #1021 for 1.0.4

After some fussing, I was able to figure out how to update with this command to prevent updating so far as to require a newer version of cargo/rust.
cargo update -p tempfile --precise 3.4.0

So the MSRV will remain at 1.61 for 1.0.4, for now.

atty is unmaintained but is still used by clap.
Disabling the default features for cbindgen removes the clap
dependency and thus removes atty.

Resolves: https://github.com/Cisco-Talos/clamav/security/dependabot/2
The build is running a different link.exe than the MSVC linker,
possibly the one provided by bash.

Fix by deleting /usr/bin/link.exe

See: https://yncat.github.io/2022/02/18/github-actions%E3%81%A7-msvc-%E3%81%AE-link-%E3%81%8C%E4%BD%BF%E3%81%88%E3%81%AA%E3%81%8F%E3%81%AA%E3%82%8B%E8%A9%B1.html
@val-ms val-ms force-pushed the CLAM-2436-no-clap-no-atty-1.0.4 branch from bc297fa to 590b2c5 Compare October 20, 2023 22:43
@val-ms val-ms merged commit 7913c21 into Cisco-Talos:dev/1.0.4 Oct 23, 2023
@val-ms val-ms deleted the CLAM-2436-no-clap-no-atty-1.0.4 branch October 23, 2023 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant