From 437f40780101fb224f48db594f13e431b52392a3 Mon Sep 17 00:00:00 2001 From: Kenneth Pernyer Date: Thu, 2 Jul 2026 10:48:40 +0200 Subject: [PATCH 1/2] chore(deps): update memmap2 0.9.11, quinn-proto 0.11.15 Clears the blocking Stability audit on main: - RUSTSEC-2026-0185: quinn-proto 0.11.14 remote memory exhaustion (7.5) - RUSTSEC-2026-0186: memmap2 0.9.10 unchecked pointer offset (unsound) Co-Authored-By: Claude Fable 5 --- Cargo.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 862847e..4a8098b 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -4512,9 +4512,9 @@ checksum = "f8ca58f447f06ed17d5fc4043ce1b10dd205e060fb3ce5b979b8ed8e59ff3f79" [[package]] name = "memmap2" -version = "0.9.10" +version = "0.9.11" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "714098028fe011992e1c3962653c96b2d578c4b4bce9036e15ff220319b1e0e3" +checksum = "d1219ed1b7f229ee7104d281dd01d6802fe28bb6e95d292942c4daacdeb798c0" dependencies = [ "libc", "stable_deref_trait", @@ -6240,9 +6240,9 @@ dependencies = [ [[package]] name = "quinn-proto" -version = "0.11.14" +version = "0.11.15" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "434b42fec591c96ef50e21e886936e66d3cc3f737104fdb9b737c40ffb94c098" +checksum = "4fcb935c5bec503c2f0e306bdd3e58bb9029dcb14fa8d9ac76e3a5256ac0763e" dependencies = [ "bytes", "getrandom 0.3.4", From 8d9f3dc1601f2ff3f9262126eb56e2f6fc860d8b Mon Sep 17 00:00:00 2001 From: Kenneth Pernyer Date: Thu, 2 Jul 2026 14:21:49 +0200 Subject: [PATCH 2/2] chore(security): quick-xml 0194/0195 transitive ignores + anyhow 1.0.103 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The 2026-07-02 advisory wave: RUSTSEC-2026-0194/0195 (quick-xml <0.41, DoS-class) are transitive via object_store, which is semver-locked upstream — no fix path until object_store releases against 0.41. Ignore lists updated in lockstep (workflows, Justfile, deny.toml). anyhow 1.0.102 (RUSTSEC-2026-0190, unsound) updated where present. Co-Authored-By: Claude Fable 5 --- .github/workflows/security.yml | 4 +++- .github/workflows/stability.yml | 4 +++- Cargo.lock | 4 ++-- deny.toml | 7 +++++++ 4 files changed, 15 insertions(+), 4 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 520a0cc..671da4f 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -31,7 +31,9 @@ jobs: cargo audit --deny warnings \ --ignore RUSTSEC-2025-0141 \ --ignore RUSTSEC-2024-0436 \ - --ignore RUSTSEC-2026-0002 && exit 0 + --ignore RUSTSEC-2026-0002 \ + --ignore RUSTSEC-2026-0194 \ + --ignore RUSTSEC-2026-0195 && exit 0 if [ "$attempt" = "3" ]; then exit 1 fi diff --git a/.github/workflows/stability.yml b/.github/workflows/stability.yml index 431d248..1c3f227 100644 --- a/.github/workflows/stability.yml +++ b/.github/workflows/stability.yml @@ -52,7 +52,9 @@ jobs: cargo audit --deny warnings \ --ignore RUSTSEC-2025-0141 \ --ignore RUSTSEC-2024-0436 \ - --ignore RUSTSEC-2026-0002 && exit 0 + --ignore RUSTSEC-2026-0002 \ + --ignore RUSTSEC-2026-0194 \ + --ignore RUSTSEC-2026-0195 && exit 0 if [ "$attempt" = "3" ]; then exit 1 fi diff --git a/Cargo.lock b/Cargo.lock index 4a8098b..ccbc6d8 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -151,9 +151,9 @@ dependencies = [ [[package]] name = "anyhow" -version = "1.0.102" +version = "1.0.103" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7f202df86484c868dbad7eaa557ef785d5c66295e41b460ef922eca0723b842c" +checksum = "2a4385e2e34eb35d6b3efe798b9eb88096925d87726c0798709bf56d9ed84af3" [[package]] name = "ar_archive_writer" diff --git a/deny.toml b/deny.toml index 619b34e..48f6b70 100644 --- a/deny.toml +++ b/deny.toml @@ -7,6 +7,13 @@ ignore = [ "RUSTSEC-2025-0141", "RUSTSEC-2024-0436", + # quick-xml <0.41 — duplicate-attribute quadratic run time (0194) and + # NsReader namespace-allocation DoS (0195), fixed in >=0.41. Transitive + # via object_store (semver-locked upstream); no fix path until upstream + # moves. XML surface is the storage provider's own API responses; both + # advisories are DoS-class. Added 2026-07-02. + "RUSTSEC-2026-0194", + "RUSTSEC-2026-0195", ] [licenses]