Skip to content

chore(deps): update crates with RustSec advisories - #511

Open
minh-tg wants to merge 2 commits into
feschber:mainfrom
minh-tg:dependency-advisory-fix
Open

minh-tg wants to merge 2 commits into
feschber:mainfrom
minh-tg:dependency-advisory-fix

Conversation

@minh-tg

@minh-tg minh-tg commented Sep 27, 2026 •

Copy link
Copy Markdown

Updates Cargo.lock to versions that fix the advisories cargo audit reports, and removes the
unused memmap dependency from input-capture.

crate from to advisories
quick-xml 0.39.2 0.41.0 RUSTSEC-2026-0194, RUSTSEC-2026-0195
rustls 0.23.37 0.23.45 RUSTSEC-2026-0285
rustls-webpki 0.103.10 0.103.15 RUSTSEC-2026-0098, RUSTSEC-2026-0099, RUSTSEC-2026-0104
anyhow 1.0.102 1.0.103 RUSTSEC-2026-0190 (unsound)
event-listener 5.4.1 5.4.2 RUSTSEC-2026-0221 (unsound)
rand 0.8.5 0.8.6 RUSTSEC-2026-0097 (unsound)

wayland-scanner also goes from 0.31.10 to 0.31.11. 0.31.10 requires quick-xml 0.39, so this
bump is what lets quick-xml move. It only runs at build time, and nothing in the workspace
uses quick-xml directly.

memmap (RUSTSEC-2020-0077, unmaintained) is not referenced anywhere in the workspace,
including build scripts and cfg-gated modules.

cargo audit reported 6 vulnerabilities before and 0 after. Four warnings remain: bincode and
paste are unmaintained, and two git2 warnings come from the shadow-rs build dependency. I left
those alone.

No code changes. cargo check, cargo clippy -D warnings, cargo fmt --check and
cargo test --workspace pass on Linux with --locked. I did not build on Windows or macOS.

@minh-tg

minh-tg commented Sep 28, 2026 •

Copy link
Copy Markdown
Author

CI is waiting for approval to run. Could a maintainer approve it when you have a moment? Thanks!

@minh-tg
minh-tg marked this pull request as ready for review September 28, 2026 13:26
Nothing in the workspace references memmap, including build scripts and
cfg-gated modules. The crate is unmaintained (RUSTSEC-2020-0077).
Bump the lockfile to versions that carry fixes:

- quick-xml 0.39.2 -> 0.41.0 (RUSTSEC-2026-0194, RUSTSEC-2026-0195)
- rustls 0.23.37 -> 0.23.45 (RUSTSEC-2026-0285)
- rustls-webpki 0.103.10 -> 0.103.15 (RUSTSEC-2026-0098,
  RUSTSEC-2026-0099, RUSTSEC-2026-0104)
- anyhow 1.0.102 -> 1.0.103 (RUSTSEC-2026-0190, unsound)
- event-listener 5.4.1 -> 5.4.2 (RUSTSEC-2026-0221, unsound)
- rand 0.8.5 -> 0.8.6 (RUSTSEC-2026-0097, unsound)

wayland-scanner moves 0.31.10 -> 0.31.11 as well. 0.31.10 requires
quick-xml 0.39, so this bump is what allows quick-xml to update. It runs
at build time only.

No code changes.
@minh-tg
minh-tg force-pushed the dependency-advisory-fix branch from eb10029 to 83f3aa4 Compare October 9, 2026 10:37
@minh-tg minh-tg changed the title fix(deps): patch inherited RustSec advisories chore(deps): update crates with RustSec advisories Oct 9, 2026
@minh-tg

minh-tg commented Oct 9, 2026

Copy link
Copy Markdown
Author

Split into two commits (the memmap removal is separate now), added the advisory IDs to the
description and commit message, and mentioned the wayland-scanner bump that quick-xml needs.
The final tree is unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant