Skip to content

fix(deps): bump vulnerable crates to patched versions#58

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/cargo-cves-2026-05-12
May 12, 2026
Merged

fix(deps): bump vulnerable crates to patched versions#58
hyperpolymath merged 1 commit into
mainfrom
fix/cargo-cves-2026-05-12

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

fix(deps): bump vulnerable crates to patched versions

Cargo.lock bumps for outstanding Dependabot alerts.
Updated 7 crate version(s) across 1 workspace(s).

Updated:

  • [czech-file-knife] aws-lc-sys -> latest (high)
  • [czech-file-knife] aws-lc-sys -> latest (high)
  • [czech-file-knife] aws-lc-sys -> latest (high)
  • [czech-file-knife] aws-lc-sys -> latest (high)
  • [czech-file-knife] aws-lc-sys -> latest (high)
  • [czech-file-knife] jsonwebtoken -> latest (medium)
  • [czech-file-knife] lru -> latest (low)

Skipped (Cargo.toml constraint blocks — manifest bump needed):

Cargo.lock bumps for outstanding Dependabot alerts.
Updated 7 crate version(s) across 1 workspace(s).

Updated:
  - [czech-file-knife] aws-lc-sys -> latest (high)
  - [czech-file-knife] aws-lc-sys -> latest (high)
  - [czech-file-knife] aws-lc-sys -> latest (high)
  - [czech-file-knife] aws-lc-sys -> latest (high)
  - [czech-file-knife] aws-lc-sys -> latest (high)
  - [czech-file-knife] jsonwebtoken -> latest (medium)
  - [czech-file-knife] lru -> latest (low)

Skipped (Cargo.toml constraint blocks — manifest bump needed):
  - [asdf-augmenters/asdf-acceleration-middleware] lru@0.16.3 (low, GHSA-rhfx-m35p-ff5j)
  - [czech-file-knife] rand@0.9.3 (low, GHSA-cq8v-f236-94qc)
  - [czech-file-knife] lz4_flex@0.11.6 (high, GHSA-vvp9-7p8x-rfvv)
  - [rescript-ecosystem/packages/bindings/tauri/examples/opsm-shell/src-tauri] rand@0.8.6 (low, GHSA-cq8v-f236-94qc)
@hyperpolymath hyperpolymath enabled auto-merge (squash) May 12, 2026 21:23
@hyperpolymath hyperpolymath merged commit 8c66300 into main May 12, 2026
6 of 19 checks passed
@hyperpolymath hyperpolymath deleted the fix/cargo-cves-2026-05-12 branch May 12, 2026 23:08
Repository owner deleted a comment from chatgpt-codex-connector Bot May 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant