show std-replacements & rustsec "unmaintained" in topbar - #3554
Merged
Merged
Conversation
syphar
force-pushed
the
rustsec-maintainenance
branch
3 times, most recently
from
September 24, 2026 09:49
8444f49 to
8b8275c
Compare
syphar
marked this pull request as ready for review
September 24, 2026 11:06
Member
Author
|
r? @GuillaumeGomez ready for a first review I think. frontend wise : i would totally use it like this, but if you want we can also iterate on other approaches :) |
syphar
marked this pull request as draft
September 24, 2026 11:23
syphar
marked this pull request as ready for review
September 24, 2026 11:27
syphar
marked this pull request as draft
September 24, 2026 11:43
Member
Author
|
@GuillaumeGomez fyi: having slept over it I think I can simplify this quite far. I also checked how many advisories there are, and std-replacements, and that changes the game. |
syphar
force-pushed
the
rustsec-maintainenance
branch
9 times, most recently
from
September 30, 2026 07:20
7bb243d to
14723d5
Compare
syphar
marked this pull request as ready for review
September 30, 2026 07:51
Member
Author
|
@GuillaumeGomez ready for a next round |
Collaborator
|
☔ The latest upstream changes (possibly #3558) made this pull request unmergeable. Please resolve the merge conflicts. |
GuillaumeGomez
approved these changes
Sep 30, 2026
syphar
force-pushed
the
rustsec-maintainenance
branch
from
September 30, 2026 13:55
14723d5 to
2e1de84
Compare
Collaborator
|
This PR was rebased onto a different main commit. Here's a range-diff highlighting what actually changed. Rebasing is a normal part of keeping PRs up to date, so no action is needed—this note is just to help reviewers. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is now a new approach for our integration with std-replacements and rustsec.
I still feel like it could be smaller, but also I want test coverage / testability to a certain extend, which enforces some design decisions.
Most important changes:
rustsec::Databaseloads everything into memory on open anyways.RwLockor something like that,ArcSwapis much better for our use-case. I hope you can excluse the additional dependency :)old description
Here we start showing _crate warnings_ in the topbar.First is the std-replacement data, and rustsec "unmaintained" warnings.
For both we have a source on github pages, which is heavily cached, and also provides a TTL in the response. So my approach here is to fetch both data sources for the crate, generate the html partial, and set the caching headers in fastly based on the cache TTL responses from gh pages.
85% of
docs_rs_reqwestis pretty standard but reduced browser / caching behaviour, but there is no usable crate in the wild that is not alpha, so I rebuilt the logic to some point. Exception from standard logic is caching of 404s even when github doesn't return a caching header for us.To parse the rustsec response, we could use the
rustseclibrary, but the structs don't provide the necessary accessors, and theosv-exportfeature pulls ingix, which we don't need and is huge). So I copied the structs as we need them for now. The logic when to show "unmaintained" and when not is coming from crates.io itself. There seem to be some progress in rustsec/rustsec#1710, let's see when that is released. Then I'll just switch back.For std-replacements, I'll start by fetching
all.jsonand just returning the crate that is asked for. Since we cache the thing, that's not too big of an issue. I'll see if we can also generate per-crate json files in gh pages later. This is also what crates.io is doing at the moment, every browser fetches the wholeall.json, and then filters for the current crate. ( at the moment it's 3k compressed).Since we only use that thing in one place / handler, I didn't invest time into adding mock / test clients to the std-replacement/rustsec libraries, for now. Of course t hat increases the amount of tests in
handlers::statusand implies the need for http mocks.first UI draft
suuper basic. When both (unmaintained & std replacement) woud be active, I'm showing another element in the topbar.
First draft of the rendering, happy to take ideas? or help?