Skip to content

Update integration-test TLS dependency chain #1

Description

@keegreil

Context

The active GridPool SV2 pool, miner, and shared workspaces pass cargo audit after the monitoring dependency update. The separate integration-tests workspace still resolves rustls-webpki 0.101.7 through the minreq / corepc test harness dependency chain.

Current audit debt in that test-only workspace:

  • RUSTSEC-2023-0071
  • RUSTSEC-2024-0336
  • RUSTSEC-2024-0381
  • Unmaintained dependency warnings in the same legacy test chain
  • rand 0.8.5 warning elsewhere in the inherited dependency graph

Scope

Update or replace the integration-test HTTP/RPC dependency chain so the integration-test lockfile passes cargo audit, without changing GridPool pool runtime behavior or destabilizing upstream SRI compatibility.

Acceptance criteria

  • cargo audit --file integration-tests/Cargo.lock reports no vulnerabilities.
  • Integration tests continue to compile and pass.
  • Any unavoidable advisory is documented with a narrow, time-bounded ignore and rationale.
  • Active runtime workspaces remain audit-clean.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions