Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enhancement: use cargo-auditable to add metadata to the binary about dependencies #404

Open
cjrh opened this issue Sep 3, 2024 · 0 comments

Comments

@cjrh
Copy link
Contributor

cjrh commented Sep 3, 2024

Now that openssl is vendored following #401, it would be a good idea to inject dependency information into the executable during the build process:

https://github.com/rust-secure-code/cargo-auditable

Tools can scan all the binaries on a system to check specifically for statically-linked binaries that have reported vulnerabilities and dramatically speed up the process of finding, updating, rebuilding, and deploying such assets.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant