Skip to content

build: patch vulnerable dependencies - #88

Merged
kev1n77 merged 1 commit into
mainfrom
codex/dependency-vulnerability-fixes
Jul 21, 2026
Merged

kev1n77 merged 1 commit into
mainfrom
codex/dependency-vulnerability-fixes

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 21, 2026

Copy link
Copy Markdown
Owner

Summary

  • patch diff to 8.0.3 without taking the unrelated 9.x major update
  • patch time to 0.3.47 in both Rust lockfiles and serde_with to 3.21.0 in the desktop lockfile
  • raise the declared Rust MSRV from 1.85 to 1.88 to match the first secure dependency releases
  • document the remaining upstream Tauri/GTK3 glib advisory and its unused vulnerable API

Dependabot alerts addressed

Verification

  • npm run desktop:check (46 tests)
  • npm run desktop:build
  • python scripts/verify_supply_chain.py
  • python -m unittest discover -s scripts/tests -v
  • Cargo formatting and metadata checks for both manifests

The remaining glib 0.18.5 alert is introduced by the latest Tauri Linux GTK3 stack. CodeIsCheap and the checked Tauri/Wry/GTK sources do not call the affected VariantStrIter API; it will be dismissed as not used while the upstream dependency is tracked.

@kev1n77
kev1n77 merged commit d6b7bad into main Jul 21, 2026
10 checks passed
@kev1n77
kev1n77 deleted the codex/dependency-vulnerability-fixes branch July 21, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant