Skip to content

chore: update bytes crate in response to security advisory#10525

Merged
bolinfest merged 1 commit intomainfrom
pr10525
Feb 3, 2026
Merged

chore: update bytes crate in response to security advisory#10525
bolinfest merged 1 commit intomainfrom
pr10525

Conversation

@bolinfest
Copy link
Collaborator

@bolinfest bolinfest commented Feb 3, 2026

While here, remove one advisory from deny.toml that has been addressed (it was showing up as a warning).

@bolinfest bolinfest requested a review from viyatb-oai February 3, 2026 16:19
Copy link
Contributor

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1b708f8954

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines 73 to 75
{ id = "RUSTSEC-2024-0388", reason = "derivative is unmaintained; pulled in via starlark v0.13.0 used by execpolicy/cli/core; no fixed release yet" },
{ id = "RUSTSEC-2025-0057", reason = "fxhash is unmaintained; pulled in via starlark_map/starlark v0.13.0 used by execpolicy/cli/core; no fixed release yet" },
{ id = "RUSTSEC-2024-0436", reason = "paste is unmaintained; pulled in via ratatui/rmcp/starlark used by tui/execpolicy; no fixed release yet" },
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep ignore for RUSTSEC-2026-0002 until lru is updated

Removing the ignore for RUSTSEC-2026-0002 will cause cargo deny check advisories to fail because the lockfile still contains lru 0.12.5 (see codex-rs/Cargo.lock around lines 4588–4595). Unless the dependency has been upgraded in the same commit, this change reintroduces a known advisory and will break the advisory check in CI.

Useful? React with 👍 / 👎.

@bolinfest bolinfest changed the title chore: remove security advisories from deny.toml that have been addressed chore: update bytes crate in response to security advisory Feb 3, 2026
@bolinfest bolinfest enabled auto-merge (squash) February 3, 2026 16:32
@bolinfest bolinfest merged commit 1634db6 into main Feb 3, 2026
80 of 85 checks passed
@bolinfest bolinfest deleted the pr10525 branch February 3, 2026 17:08
@github-actions github-actions bot locked and limited conversation to collaborators Feb 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants