In particular, this prevents errors from an old cargo-deny version, which fails to parse recent additions to the advisory database.
It won’t work, as those builds don’t have access to the CodeCov API token.