Outcome
Refresh Bodhi's existing Rust dependency baseline so current RustSec vulnerabilities are removed or explicitly dispositioned with evidence, without bundling the work into the Lotus Next package-consumer PR.
Discovery evidence
A read-only cargo audit --file src-tauri/Cargo.lock run while reviewing #65 reported 16 vulnerable package-version instances across 15 unique advisories, plus 15 maintenance/unsoundness warnings. This is confirmed pre-existing on main@518f415ca59a11e30c91456250f6167187103023: #65 changes neither src-tauri/Cargo.toml nor src-tauri/Cargo.lock, and the base/head lock SHA-256 is identically faf5a10fd516f4cb3d0a592a6fb7f5b7996ba7e1f5d7e9f935e5656c83f0e89e.
Vulnerable entries reported:
bytes 1.10.1 — RUSTSEC-2026-0007
crossbeam-epoch 0.9.18 — RUSTSEC-2026-0204
h2 0.3.27 and 0.4.10 — RUSTSEC-2026-0258
quick-xml 0.32.0 — RUSTSEC-2026-0194 / RUSTSEC-2026-0195
quinn-proto 0.11.12 — RUSTSEC-2026-0037 / RUSTSEC-2026-0185
rkyv 0.7.45 — RUSTSEC-2026-0001 / RUSTSEC-2026-0235
rustls-webpki 0.103.3 — RUSTSEC-2026-0049 / 0098 / 0099 / 0104
time 0.3.41 — RUSTSEC-2026-0009
webbrowser 1.0.4 — RUSTSEC-2026-0257
Acceptance criteria
Scope boundary
This is pre-existing dependency work discovered during #65 review. It must not change #65, expand the Lotus Next acceptance slice, or weaken any existing gate. Use its own claim, branch, isolated worktree, PR, and exact-head review.
Outcome
Refresh Bodhi's existing Rust dependency baseline so current RustSec vulnerabilities are removed or explicitly dispositioned with evidence, without bundling the work into the Lotus Next package-consumer PR.
Discovery evidence
A read-only
cargo audit --file src-tauri/Cargo.lockrun while reviewing #65 reported 16 vulnerable package-version instances across 15 unique advisories, plus 15 maintenance/unsoundness warnings. This is confirmed pre-existing onmain@518f415ca59a11e30c91456250f6167187103023: #65 changes neithersrc-tauri/Cargo.tomlnorsrc-tauri/Cargo.lock, and the base/head lock SHA-256 is identicallyfaf5a10fd516f4cb3d0a592a6fb7f5b7996ba7e1f5d7e9f935e5656c83f0e89e.Vulnerable entries reported:
bytes 1.10.1— RUSTSEC-2026-0007crossbeam-epoch 0.9.18— RUSTSEC-2026-0204h2 0.3.27and0.4.10— RUSTSEC-2026-0258quick-xml 0.32.0— RUSTSEC-2026-0194 / RUSTSEC-2026-0195quinn-proto 0.11.12— RUSTSEC-2026-0037 / RUSTSEC-2026-0185rkyv 0.7.45— RUSTSEC-2026-0001 / RUSTSEC-2026-0235rustls-webpki 0.103.3— RUSTSEC-2026-0049 / 0098 / 0099 / 0104time 0.3.41— RUSTSEC-2026-0009webbrowser 1.0.4— RUSTSEC-2026-0257Acceptance criteria
mainand map every vulnerable package to its direct dependency owner and reachable runtime/build surface.cargo auditreports zero unhandled vulnerabilities. Any advisory that truly cannot be removed has a narrow checked-in policy, concrete reachability analysis, expiry/follow-up, and reviewer approval rather than a blanket ignore.Scope boundary
This is pre-existing dependency work discovered during #65 review. It must not change #65, expand the Lotus Next acceptance slice, or weaken any existing gate. Use its own claim, branch, isolated worktree, PR, and exact-head review.