Skip to content

fix(deps): bump vulnerable transitive crates - #324

Merged
anoop-narang merged 1 commit into
mainfrom
fix/bump-vulnerable-deps
Oct 6, 2026
Merged

anoop-narang merged 1 commit into
mainfrom
fix/bump-vulnerable-deps

Conversation

@anoop-narang

@anoop-narang anoop-narang commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Lockfile-only update of transitive crates with published advisories. All move within the version ranges their dependents already allow.

  • zerovec 0.11.6 → 0.11.8, zerovec-derive 0.11.3 → 0.11.6 (GHSA-7fx9-626j-vqph)
  • quinn-proto 0.11.16 → 0.11.19
  • h2 0.4.15 → 0.4.19 (RUSTSEC-2026-0258)
  • rustls 0.23.42 → 0.23.45 (GHSA-2mjx-qc3c-rqvc, RUSTSEC-2026-0285); pulls aws-lc-rs 1.18.1, aws-lc-sys 0.45.0, rustls-webpki 0.103.15

cargo fmt --check, cargo clippy --all-targets -- -D warnings and the unit tests (538) pass locally.
cargo update also re-links dependents onto versions already in the lockfile (no new packages): colored, dirs-sys, errno, quinn-udp, rustix, rustls-platform-verifier, tempfile and winapi-util move from windows-sys 0.61.2 to 0.59.0, and tempfile from getrandom 0.4.3 to 0.3.4. Cargo 1.92, 1.96 and 1.99 all produce this same lockfile, and a no-op cargo update -p h2 --precise 0.4.15 on main re-links the same windows-sys edges, so it is how the resolver settles this graph rather than a toolchain artefact. windows-sys only builds on Windows targets.

@anoop-narang
anoop-narang requested a review from a team as a code owner October 6, 2026 07:14
@anoop-narang
anoop-narang requested review from shefeek-jinnah and removed request for a team October 6, 2026 07:14
Comment thread Cargo.lock
@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@anoop-narang
anoop-narang merged commit 66a6cd0 into main Oct 6, 2026
15 checks passed
@anoop-narang
anoop-narang deleted the fix/bump-vulnerable-deps branch October 6, 2026 07:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant