diff --git a/Cargo.toml b/Cargo.toml index 0fa4332..cf95521 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -43,9 +43,10 @@ expr-count = ["expressions", "rusty_expressions/expr-count"] [dependencies] # Optional so `default-features = false` removes it from the graph entirely. # Pin exactly: earlier releases had UAFs on all targets. Kept in step with -# rusty_expressions, which moved to 1.1.4 -- a consumer that enables both -# crates' allocators would otherwise pull two incompatible majors. -rusty_alloc-api = { version = "=1.1.6", optional = true } +# rusty_expressions, which moves to =2.2.2 alongside this -- a consumer that +# enables both crates' allocators would otherwise pull two incompatible majors. +# Releasing one without the other re-opens exactly that hazard. +rusty_alloc-api = { version = "=2.2.2", optional = true } # The Oniguruma remake, split out of this repo and published standalone. # `default-features = false` is LOAD-BEARING: rusty_expressions installs # rusty_alloc as a #[global_allocator] by default, and so does this crate -- @@ -62,3 +63,4 @@ required-features = ["a11y", "css"] [[example]] name = "expressions_demo" required-features = ["expressions"] +