Skip to content

Clear the two dependency advisories blocking cargo deny - #2

Merged
Zenofex merged 1 commit into
mainfrom
fix/dependency-advisories
Sep 24, 2026
Merged

Zenofex merged 1 commit into
mainfrom
fix/dependency-advisories

Conversation

@Zenofex

@Zenofex Zenofex commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

cargo audit + deny has been the one red check on main, before and after the correctness work. Two unrelated findings, both fixed by a lockfile bump inside the existing semver constraints.

Crate From To Why
rustls 0.23.43 0.23.45 RUSTSEC-2026-0285, medium. TLS 1.3 handshake messages accepted across encryption level boundaries. Arrives transitively via ureq.
serialport 4.10.0 4.10.1 Yanked upstream. This is the actual UART layer, so it matters beyond the warning.

No manifest changed. crates/cli/Cargo.toml already declares serialport = "4.10"; the lockfile was simply pinned to a version that no longer exists on crates.io.

Verified locally: cargo audit and cargo deny check both exit 0 with advisories, bans, licenses and sources all ok; 274 tests pass; clippy clean under -D warnings; rustfmt clean.

This should take main to fully green for the first time in this sequence.

cargo audit + deny has been the one red check on main, through the SME
correctness work and before it. Two unrelated findings, both fixed by a
lockfile bump inside the existing semver constraints.

rustls 0.23.43 carries RUSTSEC-2026-0285, medium severity: TLS 1.3 handshake
messages incorrectly accepted across encryption level boundaries. It arrives
transitively through ureq. Moved to 0.23.45, the version the advisory names.

serialport 4.10.0 was yanked upstream. Moved to 4.10.1. The manifest already
declares "4.10", so no constraint changed; the lockfile was simply pinned to
a version that no longer exists on crates.io. This one matters beyond the
warning, since serialport is the actual UART layer.

Verified: cargo audit and cargo deny check both exit 0, with advisories,
bans, licenses and sources all ok. 274 tests pass, clippy is clean under
-D warnings, and rustfmt is clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Zenofex
Zenofex merged commit d743429 into main Sep 24, 2026
11 checks passed
@Zenofex
Zenofex deleted the fix/dependency-advisories branch September 24, 2026 09:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant