Skip to content

tdx: bump rand to 0.10.2 to fix CVE - #24

Merged
guzongmin merged 1 commit into
mainfrom
zhoul1/dev/OpenCVE_2
Sep 16, 2026
Merged

guzongmin merged 1 commit into
mainfrom
zhoul1/dev/OpenCVE_2

Conversation

@liangzhou121

Copy link
Copy Markdown
Contributor

Update rand from 0.10.0 to 0.10.2 in test_infra/Cargo.toml and refresh Cargo.lock accordingly to address a known CVE(Rand is unsound with a custom logger using rand::rng()) in rand 0.10.0.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues were identified.

Pull request overview

Updates rand from 0.10.0 to 0.10.2 to address the reported security issue and refresh dependency resolution.

Changes:

  • Bumps the direct rand dependency.
  • Refreshes both lockfiles, checksums, and related resolutions.
File summaries
File Description
test_infra/Cargo.toml Bumps rand to 0.10.2.
fuzz/Cargo.lock Updates fuzzing dependency resolution.
Cargo.lock Records updated dependency resolutions.
Review details
  • Files reviewed: 1/3 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Update rand from 0.10.0 to 0.10.2 in test_infra/Cargo.toml and refresh
Cargo.lock accordingly to address a known CVE(Rand is unsound with a
custom logger using rand::rng()) in rand 0.10.0.

Signed-off-by: Liang, Zhou <liang1.zhou@intel.com>

@guzongmin guzongmin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@guzongmin
guzongmin merged commit 2230938 into main Sep 16, 2026
18 of 44 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants