Skip to content
This repository was archived by the owner on Aug 7, 2026. It is now read-only.

chore(deps): clear RUSTSEC-2026-0185/0186 (quinn-proto, memmap2) - #20

Merged
kpernyer merged 2 commits into
mainfrom
next
Jul 2, 2026
Merged

kpernyer merged 2 commits into
mainfrom
next

Conversation

@kpernyer

@kpernyer kpernyer commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Fixes the Stability (blocking security audit) failure on main from 2026-06-29.

  • cargo update -p memmap2 → 0.9.11 (RUSTSEC-2026-0186, unsound pointer offset)
  • cargo update -p quinn-proto → 0.11.15 (RUSTSEC-2026-0185, remote memory exhaustion, severity 7.5)

Verified locally: cargo check --workspace --all-targets clean.

🤖 Generated with Claude Code


Note

Low Risk
Supply-chain maintenance only: patch dependency updates and documented advisory allowlists; no application logic changes.

Overview
Unblocks Stability / Security cargo-audit by refreshing the lockfile and aligning advisory exceptions across CI and cargo-deny.

Lockfile: bumps memmap2 to 0.9.11 and quinn-proto to 0.11.15 (plus minor anyhow patch), addressing the blocking RustSec issues called out for those crates.

Policy: adds RUSTSEC-2026-0194 and RUSTSEC-2026-0195 (transitive quick-xml <0.41 via object_store, DoS-class, no semver fix yet) to deny.toml and the same --ignore list in .github/workflows/security.yml and stability.yml, with rationale documented in deny.toml.

Reviewed by Cursor Bugbot for commit 8d9f3dc. Bugbot is set up for automated code reviews on this repo. Configure here.

Clears the blocking Stability audit on main:
- RUSTSEC-2026-0185: quinn-proto 0.11.14 remote memory exhaustion (7.5)
- RUSTSEC-2026-0186: memmap2 0.9.10 unchecked pointer offset (unsound)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cursor

cursor Bot commented Jul 2, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_b4d64f31-2727-4f67-b092-110881179b6b)

The 2026-07-02 advisory wave: RUSTSEC-2026-0194/0195 (quick-xml <0.41,
DoS-class) are transitive via object_store, which is semver-locked
upstream — no fix path until object_store releases against 0.41.
Ignore lists updated in lockstep (workflows, Justfile, deny.toml).
anyhow 1.0.102 (RUSTSEC-2026-0190, unsound) updated where present.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cursor

cursor Bot commented Jul 2, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_c07759aa-d64c-4311-b65d-fa268704e24d)

@kpernyer
kpernyer merged commit 78333c6 into main Jul 2, 2026
14 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant