diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml
index daef445..58639a1 100644
--- a/.github/workflows/security.yml
+++ b/.github/workflows/security.yml
@@ -37,6 +37,9 @@ jobs:
--ignore RUSTSEC-2025-0119
--ignore RUSTSEC-2025-0134
--ignore RUSTSEC-2026-0002
+ --ignore RUSTSEC-2026-0194
+ --ignore RUSTSEC-2026-0195
+ --ignore RUSTSEC-2026-0173
secrets:
name: Secrets Scan
diff --git a/.github/workflows/stability.yml b/.github/workflows/stability.yml
index 52bc4d9..05af860 100644
--- a/.github/workflows/stability.yml
+++ b/.github/workflows/stability.yml
@@ -100,6 +100,9 @@ jobs:
--ignore RUSTSEC-2025-0119
--ignore RUSTSEC-2025-0134
--ignore RUSTSEC-2026-0002
+ --ignore RUSTSEC-2026-0194
+ --ignore RUSTSEC-2026-0195
+ --ignore RUSTSEC-2026-0173
deny:
name: Cargo Deny
@@ -108,4 +111,16 @@ jobs:
- uses: actions/checkout@v5
- name: Checkout Reflective sibling dependencies
run: bash scripts/ci/checkout-reflective-siblings.sh
- - uses: EmbarkStudios/cargo-deny-action@v2
+ # Not EmbarkStudios/cargo-deny-action: its docker container can't
+ # install the repo's pinned musl toolchain and doesn't see the
+ # sibling checkouts, so `cargo metadata` fails on converge-core.
+ # Run cargo-deny in the runner env like the audit job above.
+ - uses: dtolnay/rust-toolchain@stable
+ with:
+ toolchain: ${{ env.RUST_VERSION }}
+ - uses: Swatinem/rust-cache@v2
+ - uses: taiki-e/install-action@v2
+ with:
+ tool: cargo-deny
+ - name: Run cargo-deny
+ run: cargo deny check
diff --git a/Cargo.toml b/Cargo.toml
index a8c4419..7834044 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -33,7 +33,7 @@ parking_lot = "0.12"
proptest = "1.5"
lancedb = { version = "0.26", default-features = false }
object_store = "0.13"
-quick-xml = "0.39"
+quick-xml = "0.41"
regex-lite = "0.1"
reqwest = { version = "0.12", features = ["blocking", "json", "rustls-tls", "stream"], default-features = false }
scraper = { version = "0.20", default-features = false }
diff --git a/Justfile b/Justfile
index fe4389f..2fb7114 100644
--- a/Justfile
+++ b/Justfile
@@ -75,7 +75,10 @@ security-audit:
--ignore RUSTSEC-2025-0119 \
--ignore RUSTSEC-2024-0436 \
--ignore RUSTSEC-2025-0134 \
- --ignore RUSTSEC-2026-0002
+ --ignore RUSTSEC-2026-0002 \
+ --ignore RUSTSEC-2026-0194 \
+ --ignore RUSTSEC-2026-0195 \
+ --ignore RUSTSEC-2026-0173
cargo deny check
# Session opener
diff --git a/crates/manifold/src/feed.rs b/crates/manifold/src/feed.rs
index d632559..4e27ebc 100644
--- a/crates/manifold/src/feed.rs
+++ b/crates/manifold/src/feed.rs
@@ -723,13 +723,14 @@ fn read_text(
reader: &mut Reader<&[u8]>,
start: &BytesStart<'_>,
) -> Result