GHSA-m2xr-2vj4-wh94: tanton_engine has unsound public API
The following functions in the tanton_engine
crate are unsound due to lack of sufficient boundary
checks in public API:
Stack::offset()
ThreadStack::get()
RootMoveList::insert_score_depth()
RootMoveList::insert_score()
The tanton_engine crate is no longer maintained, so there are no plans to fix this issue.
References
Code Behaviors & Features
Detect and mitigate GHSA-m2xr-2vj4-wh94 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →