Skip to content

Patch audited dependencies and reconcile consensus docs - #3

Merged
maximilliangrand merged 1 commit into
masterfrom
fix/security-docs-dependencies
Sep 8, 2026
Merged

maximilliangrand merged 1 commit into
masterfrom
fix/security-docs-dependencies

Conversation

@maximilliangrand

Copy link
Copy Markdown
Owner

The dependency security audit fails on bytes 1.11.0 and crossbeam-epoch 0.9.18 and reports an anyhow 1.0.100 unsoundness warning. Update only those root lockfile resolutions to patched versions: bytes 1.11.1, crossbeam-epoch 0.9.20, and anyhow 1.0.103. No advisories are suppressed. The fuzz lockfile already has newer patched resolutions and is unchanged.

Align the README and threat-model summary with the existing heaviest-work fork choice and bounded peer table. Preserve educational positioning and the remaining peer, mempool, and key-storage limitations.

Local verification: cargo test --all-features --locked and cargo clippy --all-targets --all-features --locked -- -D warnings pass on macOS with Rust 1.98. CI provides the minimum-supported-version, current advisory database, release build and fuzz checks.

@maximilliangrand
maximilliangrand merged commit 18cfe60 into master Sep 8, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant