Skip to content

fix(deps): update dependencies with security advisories - #52

Open
lexfrei wants to merge 4 commits into
masterfrom
fix/dependency-advisories
Open

lexfrei wants to merge 4 commits into
masterfrom
fix/dependency-advisories

Conversation

@lexfrei

@lexfrei lexfrei commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

This closes all open Dependabot alerts with a lockfile update. openssl, bytes, time, serde_with, rand and tracing-subscriber move to their latest compatible releases. rustls goes to the last 0.23 release, which brings in rustls-webpki 0.103 with the fix.

The whole lockfile is refreshed, including crates without alerts. h2 and event-listener were pinned at versions with published advisories that Dependabot had not reported, and the refresh takes both past the fixed versions.

Direct dependencies move to their latest release within the current major version. tikv-jemallocator goes from 0.6 to 0.7, which is a major version, but it needs no code change and JEMALLOC_SYS_WITH_MALLOC_CONF in the Dockerfile works the same way. kube, k8s-openapi and hcloud need code changes to update, and those would conflict with #37, #47 and #49, so they are in #50.

The tokio time feature is now declared in Cargo.toml. It used to reach tokio only through kube and reqwest, so the build depended on what those crates enable.

The builder image moves from Rust 1.82 to 1.98, the current stable, which CI tracks. The updated time crate is published with the 2024 edition, which 1.82 cannot build. I built the image and ran it.

One doc comment is split. The updated tracing-attributes makes clippy report the first paragraph of the reconcile_service doc comment as too long. Otherwise clippy reports the same warnings as on master.

The lockfile pinned openssl, rustls-webpki, bytes, time, serde_with,
rand and tracing-subscriber at versions with published advisories. They
move to their latest compatible releases, and rustls to the last 0.23
release, which is what brings in the fixed rustls-webpki. Direct
dependencies go to their latest release within the current major
version, and tikv-jemallocator to 0.7, which needs no code change.

The builder image moves from Rust 1.82 to 1.98, the version CI uses:
the updated time crate is published with the 2024 edition, which 1.82
cannot build.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>
tokio::time is about to be used directly for short retries, while the
time feature only reached tokio through kube and reqwest. Declaring it
keeps the build from depending on what those crates enable.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>
The lockfile still pinned h2 and event-listener at versions with
published advisories (unbounded empty DATA frames in h2, !Send tags in
event-listener) that Dependabot had not reported. Every dependency
moves to its latest release compatible with Cargo.toml, which takes
both past the fixed versions.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>
The updated tracing-attributes keeps the span of doc comments on
instrumented functions, so clippy now reports the four-line first
paragraph of reconcile_service as too long.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant