diff --git a/supply-chain/config.toml b/supply-chain/config.toml index 3da872b6..793d7af5 100644 --- a/supply-chain/config.toml +++ b/supply-chain/config.toml @@ -36,7 +36,7 @@ version = "0.7.8" criteria = "safe-to-deploy" [[exemptions.bitflags]] -version = "2.13.1" +version = "2.13.2" criteria = "safe-to-deploy" [[exemptions.block-buffer]] @@ -56,11 +56,11 @@ version = "1.5.0" criteria = "safe-to-run" [[exemptions.cc]] -version = "1.4.4" +version = "1.4.6" criteria = "safe-to-deploy" [[exemptions.cfg-if]] -version = "1.0.4" +version = "1.0.5" criteria = "safe-to-deploy" [[exemptions.chrono]] @@ -96,7 +96,7 @@ version = "0.3.1" criteria = "safe-to-deploy" [[exemptions.crc32fast]] -version = "1.5.1" +version = "1.5.2" criteria = "safe-to-deploy" [[exemptions.criterion]] @@ -108,19 +108,19 @@ version = "0.8.2" criteria = "safe-to-run" [[exemptions.crossbeam-channel]] -version = "0.5.16" +version = "0.5.17" criteria = "safe-to-deploy" [[exemptions.crossbeam-deque]] -version = "0.8.7" +version = "0.8.8" criteria = "safe-to-deploy" [[exemptions.crossbeam-epoch]] -version = "0.9.20" +version = "0.9.21" criteria = "safe-to-deploy" [[exemptions.crossbeam-utils]] -version = "0.8.22" +version = "0.8.23" criteria = "safe-to-deploy" [[exemptions.crypto-common]] @@ -163,10 +163,6 @@ criteria = "safe-to-deploy" version = "0.2.29" criteria = "safe-to-deploy" -[[exemptions.find-msvc-tools]] -version = "0.1.11" -criteria = "safe-to-deploy" - [[exemptions.flate2]] version = "1.1.10" criteria = "safe-to-deploy" @@ -224,7 +220,7 @@ version = "1.10.1" criteria = "safe-to-deploy" [[exemptions.hybrid-array]] -version = "0.4.14" +version = "0.4.15" criteria = "safe-to-deploy" [[exemptions.iana-time-zone]] @@ -268,7 +264,7 @@ version = "1.2.2" criteria = "safe-to-deploy" [[exemptions.indexmap]] -version = "2.14.1" +version = "2.14.2" criteria = "safe-to-deploy" [[exemptions.itertools]] @@ -276,11 +272,11 @@ version = "0.13.0" criteria = "safe-to-run" [[exemptions.jiff-core]] -version = "0.1.0" +version = "0.1.1" criteria = "safe-to-deploy" [[exemptions.js-sys]] -version = "0.3.104" +version = "0.3.105" criteria = "safe-to-deploy" [[exemptions.json5]] @@ -323,6 +319,14 @@ criteria = "safe-to-deploy" version = "0.9.1" criteria = "safe-to-deploy" +[[exemptions.multiversion]] +version = "0.9.0" +criteria = "safe-to-deploy" + +[[exemptions.multiversion-macros]] +version = "0.9.0" +criteria = "safe-to-deploy" + [[exemptions.nonempty]] version = "0.12.0" criteria = "safe-to-deploy" @@ -364,7 +368,7 @@ version = "1.15.0" criteria = "safe-to-deploy" [[exemptions.portable-atomic-util]] -version = "0.2.7" +version = "0.2.8" criteria = "safe-to-deploy" [[exemptions.potential_utf]] @@ -384,7 +388,7 @@ version = "0.17.14" criteria = "safe-to-deploy" [[exemptions.rustix]] -version = "1.1.4" +version = "1.1.5" criteria = "safe-to-deploy" [[exemptions.rustls]] @@ -423,10 +427,6 @@ criteria = "safe-to-deploy" version = "0.11.0" criteria = "safe-to-deploy" -[[exemptions.shlex]] -version = "2.0.1" -criteria = "safe-to-deploy" - [[exemptions.simd-adler32]] version = "0.3.10" criteria = "safe-to-deploy" @@ -436,7 +436,7 @@ version = "0.4.12" criteria = "safe-to-deploy" [[exemptions.smallvec]] -version = "1.16.0" +version = "1.16.1" criteria = "safe-to-deploy" [[exemptions.stable_deref_trait]] @@ -447,6 +447,10 @@ criteria = "safe-to-deploy" version = "2.6.1" criteria = "safe-to-deploy" +[[exemptions.synstructure]] +version = "0.14.0" +criteria = "safe-to-deploy" + [[exemptions.tempfile]] version = "3.27.0" criteria = "safe-to-deploy" @@ -468,7 +472,7 @@ version = "0.8.4" criteria = "safe-to-deploy" [[exemptions.tinyvec]] -version = "1.12.0" +version = "1.13.3" criteria = "safe-to-deploy" [[exemptions.tracing]] @@ -532,23 +536,23 @@ version = "0.11.1+wasi-snapshot-preview1" criteria = "safe-to-deploy" [[exemptions.wasm-bindgen]] -version = "0.2.127" +version = "0.2.128" criteria = "safe-to-deploy" [[exemptions.wasm-bindgen-macro]] -version = "0.2.127" +version = "0.2.128" criteria = "safe-to-deploy" [[exemptions.wasm-bindgen-macro-support]] -version = "0.2.127" +version = "0.2.128" criteria = "safe-to-deploy" [[exemptions.wasm-bindgen-shared]] -version = "0.2.127" +version = "0.2.128" criteria = "safe-to-deploy" [[exemptions.web-sys]] -version = "0.3.104" +version = "0.3.105" criteria = "safe-to-run" [[exemptions.webpki-roots]] @@ -604,15 +608,15 @@ version = "0.8.3" criteria = "safe-to-deploy" [[exemptions.yoke-derive]] -version = "0.8.2" +version = "0.8.3" criteria = "safe-to-deploy" [[exemptions.zerocopy]] -version = "0.8.56" +version = "0.8.57" criteria = "safe-to-run" [[exemptions.zerocopy-derive]] -version = "0.8.56" +version = "0.8.57" criteria = "safe-to-run" [[exemptions.zerofrom]] @@ -620,7 +624,7 @@ version = "0.1.8" criteria = "safe-to-deploy" [[exemptions.zerofrom-derive]] -version = "0.1.7" +version = "0.1.8" criteria = "safe-to-deploy" [[exemptions.zeroize]] @@ -636,5 +640,5 @@ version = "0.11.6" criteria = "safe-to-deploy" [[exemptions.zlib-rs]] -version = "0.6.7" +version = "0.6.8" criteria = "safe-to-deploy" diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock index d9ca5114..0f6326c6 100644 --- a/supply-chain/imports.lock +++ b/supply-chain/imports.lock @@ -86,36 +86,36 @@ user-login = "BurntSushi" user-name = "Andrew Gallant" [[publisher.clap]] -version = "4.6.6" -when = "2026-08-06" +version = "4.6.7" +when = "2026-09-14" user-id = 6743 user-login = "epage" user-name = "Ed Page" [[publisher.clap_builder]] -version = "4.6.6" -when = "2026-08-06" +version = "4.6.7" +when = "2026-09-14" user-id = 6743 user-login = "epage" user-name = "Ed Page" [[publisher.clap_complete]] -version = "4.6.9" -when = "2026-08-06" +version = "4.6.11" +when = "2026-09-15" user-id = 6743 user-login = "epage" user-name = "Ed Page" [[publisher.clap_derive]] -version = "4.6.4" -when = "2026-07-21" +version = "4.6.7" +when = "2026-09-14" user-id = 6743 user-login = "epage" user-name = "Ed Page" [[publisher.clap_lex]] -version = "1.1.0" -when = "2026-03-12" +version = "1.1.1" +when = "2026-09-14" user-id = 6743 user-login = "epage" user-name = "Ed Page" @@ -149,8 +149,8 @@ user-login = "cuviper" user-name = "Josh Stone" [[publisher.encoding_rs]] -version = "0.8.35" -when = "2024-10-24" +version = "0.8.41" +when = "2026-09-09" user-id = 4484 user-login = "hsivonen" user-name = "Henri Sivonen" @@ -162,6 +162,13 @@ user-id = 539 user-login = "cuviper" user-name = "Josh Stone" +[[publisher.find-msvc-tools]] +version = "0.1.0" +when = "2025-08-29" +user-id = 539 +user-login = "cuviper" +user-name = "Josh Stone" + [[publisher.gix]] version = "0.87.1" when = "2026-08-24" @@ -513,15 +520,15 @@ user-login = "dtolnay" user-name = "David Tolnay" [[publisher.jiff]] -version = "0.2.35" -when = "2026-07-25" +version = "0.2.37" +when = "2026-09-12" user-id = 189 user-login = "BurntSushi" user-name = "Andrew Gallant" [[publisher.jiff-static]] -version = "0.2.35" -when = "2026-07-25" +version = "0.2.37" +when = "2026-09-12" user-id = 189 user-login = "BurntSushi" user-name = "Andrew Gallant" @@ -553,6 +560,13 @@ user-id = 189 user-login = "BurntSushi" user-name = "Andrew Gallant" +[[publisher.multiversion_no_op]] +version = "1.0.0" +when = "2026-07-30" +user-id = 4484 +user-login = "hsivonen" +user-name = "Henri Sivonen" + [[publisher.once_cell_polyfill]] version = "1.70.2" when = "2025-10-21" @@ -680,8 +694,8 @@ user-login = "dtolnay" user-name = "David Tolnay" [[publisher.syn]] -version = "3.0.4" -when = "2026-08-24" +version = "3.0.6" +when = "2026-09-16" user-id = 3618 user-login = "dtolnay" user-name = "David Tolnay" @@ -736,8 +750,8 @@ user-login = "BurntSushi" user-name = "Andrew Gallant" [[publisher.unicode-ident]] -version = "1.0.24" -when = "2026-02-16" +version = "1.0.26" +when = "2026-09-17" user-id = 3618 user-login = "dtolnay" user-name = "David Tolnay" @@ -750,15 +764,15 @@ user-login = "Manishearth" user-name = "Manish Goregaokar" [[publisher.ureq]] -version = "3.4.1" -when = "2026-09-06" +version = "3.4.2" +when = "2026-09-13" user-id = 5441 user-login = "algesten" user-name = "Martin Algesten" [[publisher.ureq-proto]] -version = "0.6.2" -when = "2026-09-06" +version = "0.6.4" +when = "2026-09-16" user-id = 5441 user-login = "algesten" user-name = "Martin Algesten" @@ -922,6 +936,12 @@ who = "Dan Gohman " criteria = "safe-to-deploy" delta = "0.3.9 -> 0.3.10" +[[audits.bytecode-alliance.audits.find-msvc-tools]] +who = "Alex Crichton " +criteria = "safe-to-deploy" +delta = "0.1.0 -> 0.1.4" +notes = "Nothing out of the ordinary for a crate finding MSVC tooling." + [[audits.bytecode-alliance.audits.foldhash]] who = "Alex Crichton " criteria = "safe-to-deploy" @@ -987,15 +1007,11 @@ criteria = "safe-to-deploy" version = "0.1.4" notes = "I always really enjoy reading eliza's code, she left perfect comments at every use of unsafe." -[[audits.bytecode-alliance.audits.tinyvec_macros]] +[[audits.bytecode-alliance.audits.shlex]] who = "Alex Crichton " criteria = "safe-to-deploy" -version = "0.1.0" -notes = """ -This is a trivial crate which only contains a singular macro definition which is -intended to multiplex across the internal representation of a tinyvec, -presumably. This trivially doesn't contain anything bad. -""" +version = "1.1.0" +notes = "Only minor `unsafe` code blocks which look valid and otherwise does what it says on the tin." [[audits.google.audits.bitflags]] who = "Lukasz Anforowicz " @@ -1126,6 +1142,15 @@ end = "2027-09-07" notes = "I, Henri Sivonen, wrote encoding_rs for Gecko and have reviewed contributions by others." aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" +[[audits.mozilla.wildcard-audits.multiversion_no_op]] +who = "Henri Sivonen " +criteria = "safe-to-deploy" +user-id = 4484 # Henri Sivonen (hsivonen) +start = "2026-07-30" +end = "2027-08-06" +notes = "I, Henri Sivonen, am the sole author of multiversion_no_op (which is a trivial crate)." +aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" + [[audits.mozilla.wildcard-audits.unicode-normalization]] who = "Manish Goregaokar " criteria = "safe-to-deploy" @@ -1168,6 +1193,12 @@ criteria = "safe-to-deploy" delta = "0.8.6 -> 0.8.7" aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" +[[audits.mozilla.audits.core_detect]] +who = "Henri Sivonen " +criteria = "safe-to-deploy" +version = "1.0.0" +aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" + [[audits.mozilla.audits.crunchy]] who = "Erich Gubler " criteria = "safe-to-deploy" @@ -1228,6 +1259,19 @@ criteria = "safe-to-deploy" delta = "0.3.1 -> 0.3.3" aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" +[[audits.mozilla.audits.find-msvc-tools]] +who = "Jan-Erik Rediger " +criteria = "safe-to-deploy" +delta = "0.1.4 -> 0.1.8" +aggregated-from = "https://raw.githubusercontent.com/mozilla/glean/main/supply-chain/audits.toml" + +[[audits.mozilla.audits.find-msvc-tools]] +who = "Emilio Cobos Álvarez " +criteria = "safe-to-deploy" +delta = "0.1.8 -> 0.1.12" +notes = "Pretty minor changes, no new unsafe code." +aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" + [[audits.mozilla.audits.fnv]] who = "Bobby Holley " criteria = "safe-to-deploy" @@ -1341,41 +1385,34 @@ criteria = "safe-to-deploy" delta = "0.1.4 -> 0.1.7" aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" -[[audits.mozilla.audits.strsim]] -who = "Ben Dean-Kawamura " +[[audits.mozilla.audits.shlex]] +who = "Max Inden " criteria = "safe-to-deploy" -delta = "0.10.0 -> 0.11.1" +delta = "1.1.0 -> 1.3.0" aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" -[[audits.mozilla.audits.synstructure]] -who = "Nika Layzell " +[[audits.mozilla.audits.shlex]] +who = "Emilio Cobos Álvarez " criteria = "safe-to-deploy" -version = "0.12.6" +delta = "1.3.0 -> 2.0.1" notes = """ -I am the primary author of the `synstructure` crate, and its current -maintainer. The one use of `unsafe` is unnecessary, but documented and -harmless. It will be removed in the next version. +Mostly removes some deprecated and unsound APIs. """ aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" -[[audits.mozilla.audits.synstructure]] -who = "Mike Hommey " +[[audits.mozilla.audits.simdutf8]] +who = "Henri Sivonen " criteria = "safe-to-deploy" -delta = "0.12.6 -> 0.13.0" +version = "0.1.5" +notes = "Confidence in correctness of the algorithm is based on fuzzing the SSE 4.2 and AVX2 implementations rather than working through the logic of the code. Audit of aarch64 and Wasm is by comparing the code with the SSE 4.2 case." aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" -[[audits.mozilla.audits.synstructure]] -who = "Mike Hommey " +[[audits.mozilla.audits.strsim]] +who = "Ben Dean-Kawamura " criteria = "safe-to-deploy" -delta = "0.13.0 -> 0.13.1" +delta = "0.10.0 -> 0.11.1" aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" -[[audits.mozilla.audits.synstructure]] -who = "Nika Layzell " -criteria = "safe-to-deploy" -delta = "0.13.1 -> 0.13.2" -aggregated-from = "https://raw.githubusercontent.com/mozilla/cargo-vet/main/supply-chain/audits.toml" - [[audits.mozilla.audits.time-core]] who = "Kershaw Chang " criteria = "safe-to-deploy" @@ -1407,12 +1444,6 @@ delta = "0.1.4 -> 0.1.8" notes = "No unsafe code" aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" -[[audits.mozilla.audits.tinyvec_macros]] -who = "Drew Willcoxon " -criteria = "safe-to-deploy" -delta = "0.1.0 -> 0.1.1" -aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" - [[audits.mozilla.audits.utf8parse]] who = "Nika Layzell " criteria = "safe-to-deploy"