Repository navigation
Conversation
Clears 4 of 6 reported vulnerabilities. All were transitive, none direct. - RUSTSEC-2026-0258 (h2 unbounded empty DATA frames): h2 0.4.15 -> 0.4.16 - RUSTSEC-2026-0204 (invalid pointer deref in fmt::Pointer): crossbeam-epoch 0.9.18 -> 0.9.20 - RUSTSEC-2026-0195 / RUSTSEC-2026-0194 (quick-xml 0.38.4): cleared by bumping cartog 0.30.2 -> 0.32.2 with default-features = false, which drops the remote-s3 feature and with it rust-s3 -> quick-xml 0.38. Only the local graph DB API is used, so no functionality is lost. Not fixed (no upstream release exists): - RUSTSEC-2026-0195 / RUSTSEC-2026-0194 (quick-xml 0.37.5) reach the tree via self_update 0.42, a mandatory cartog dependency that pins quick-xml ^0.37. quick-xml is non-optional in self_update and its latest release (0.44) still requires only ^0.38, so no published version satisfies the >= 0.41 fix. Resolving this requires an upstream self_update release. number_prefix and paste remain unmaintained warnings only, as before.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Cargo manifest updates ChangesCartog dependency configuration
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This PR updates transitive dependencies and disables unused default features without application-code changes; no actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #38 +/- ##
=======================================
Coverage 80.64% 80.64%
=======================================
Files 27 27
Lines 7540 7540
=======================================
Hits 6081 6081
Misses 1459 1459 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Resolves 4 of 6 vulnerabilities reported by
cargo audit. All were transitive; none is a direct dependency of this workspace.Results
cargo audit: 6 vulnerabilities -> 2. No new advisories appeared.Changes
h2andcrossbeam-epoch: lockfile-only bumps (cargo update -p), no manifest change needed.cartog0.30.2 -> 0.32.2withdefault-features = false.The
cartogdefault feature set includesremote-s3, which pullsrust-s3->aws-creds->quick-xml 0.38. This workspace only usescartog::db::Databaseandcartog::types(the local SQLite graph) and never uses S3, LSP, or embedding features, so disabling default features drops that path entirely rather than masking it. A comment inCargo.tomlrecords why, to stop the feature being re-enabled by accident.No application code changes were required.
Left unfixed, with reason
quick-xml 0.37.5reaches the tree throughself_update 0.42.0, a mandatory (non-optional) dependency ofcartogthat pinsquick-xml = "0.37". The fix requires>= 0.41.0, and:quick-xmlis not feature-gated inself_update— its S3 backend is always compiled, so no feature flag removes it.self_update(0.44.0) still requires only^0.38, which is itself vulnerable. No publishedself_updaterelease depends on a fixedquick-xml.[patch]is rejected by Cargo, and forcing a multi-major0.37 -> 0.41bump under a crate not written against that API would not produce a tree that compiles.This needs an upstream
self_updaterelease, then acartogbump. Forcing it here was deliberately avoided rather than shipping a broken tree.Out of scope (unchanged, warnings only)
number_prefix0.4.0 (RUSTSEC-2025-0119) andpaste1.0.15 (RUSTSEC-2024-0436) remain unmaintained warnings, not vulnerabilities — same status as before this change.Verification
cargo build --all-targets— passescargo test --workspace— 381 passed, 0 failedcargo fmt --check— cleancargo deny check advisories— FAILS on the two remainingquick-xml 0.37.5advisories above; nothing elsecargo clippy --workspace --all-targets -- -D warnings— 2 errors (redundant reference in println! argument), pre-existing: verified by stashing and re-running on cleanmain, which reproduces the identical 2 errors. Unrelated to dependencies and left untouched.Summary by CodeRabbit