From 19d6805301c67ba057eb0fa0639c25b7d23b4131 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Mon, 14 Sep 2026 14:29:40 +0000 Subject: [PATCH] chore(security): refresh cargo-vet imports Scheduled weekly refresh of supply-chain/imports.lock from upstream audit sources (Mozilla, Google, Bytecode Alliance, ISRG, Zcash). See .github/workflows/cargo-vet-refresh.yml for rationale and docs/architecture/security/ supply-chain-posture.md for the full supply-chain posture. --- supply-chain/config.toml | 8 -------- supply-chain/imports.lock | 28 ++++++++++++++++++++++++++++ 2 files changed, 28 insertions(+), 8 deletions(-) diff --git a/supply-chain/config.toml b/supply-chain/config.toml index 8cda56f11..ee7ac0aa5 100644 --- a/supply-chain/config.toml +++ b/supply-chain/config.toml @@ -842,10 +842,6 @@ criteria = "safe-to-deploy" version = "0.11.0" criteria = "safe-to-deploy" -[[exemptions.shlex]] -version = "2.0.1" -criteria = "safe-to-deploy" - [[exemptions.signal-hook]] version = "0.4.4" criteria = "safe-to-deploy" @@ -862,10 +858,6 @@ criteria = "safe-to-deploy" version = "0.17.0" criteria = "safe-to-deploy" -[[exemptions.simdutf8]] -version = "0.1.5" -criteria = "safe-to-deploy" - [[exemptions.siphasher]] version = "1.0.2" criteria = "safe-to-deploy" diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock index d249932f0..fe41852a2 100644 --- a/supply-chain/imports.lock +++ b/supply-chain/imports.lock @@ -935,6 +935,12 @@ criteria = "safe-to-deploy" version = "0.1.4" notes = "I always really enjoy reading eliza's code, she left perfect comments at every use of unsafe." +[[audits.bytecode-alliance.audits.shlex]] +who = "Alex Crichton " +criteria = "safe-to-deploy" +version = "1.1.0" +notes = "Only minor `unsafe` code blocks which look valid and otherwise does what it says on the tin." + [[audits.bytecode-alliance.audits.smallvec]] who = "Alex Crichton " criteria = "safe-to-deploy" @@ -1853,6 +1859,28 @@ criteria = "safe-to-deploy" delta = "0.1.4 -> 0.1.7" aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" +[[audits.mozilla.audits.shlex]] +who = "Max Inden " +criteria = "safe-to-deploy" +delta = "1.1.0 -> 1.3.0" +aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" + +[[audits.mozilla.audits.shlex]] +who = "Emilio Cobos Álvarez " +criteria = "safe-to-deploy" +delta = "1.3.0 -> 2.0.1" +notes = """ +Mostly removes some deprecated and unsound APIs. +""" +aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" + +[[audits.mozilla.audits.simdutf8]] +who = "Henri Sivonen " +criteria = "safe-to-deploy" +version = "0.1.5" +notes = "Confidence in correctness of the algorithm is based on fuzzing the SSE 4.2 and AVX2 implementations rather than working through the logic of the code. Audit of aarch64 and Wasm is by comparing the code with the SSE 4.2 case." +aggregated-from = "https://hg.mozilla.org/mozilla-central/raw-file/tip/supply-chain/audits.toml" + [[audits.mozilla.audits.smallvec]] who = "Erich Gubler " criteria = "safe-to-deploy"