Skip to content

[bodhi] chore: refresh vulnerable Rust dependency baseline #66

Description

@bigduu

Outcome

Refresh Bodhi's existing Rust dependency baseline so current RustSec vulnerabilities are removed or explicitly dispositioned with evidence, without bundling the work into the Lotus Next package-consumer PR.

Discovery evidence

A read-only cargo audit --file src-tauri/Cargo.lock run while reviewing #65 reported 16 vulnerable package-version instances across 15 unique advisories, plus 15 maintenance/unsoundness warnings. This is confirmed pre-existing on main@518f415ca59a11e30c91456250f6167187103023: #65 changes neither src-tauri/Cargo.toml nor src-tauri/Cargo.lock, and the base/head lock SHA-256 is identically faf5a10fd516f4cb3d0a592a6fb7f5b7996ba7e1f5d7e9f935e5656c83f0e89e.

Vulnerable entries reported:

  • bytes 1.10.1 — RUSTSEC-2026-0007
  • crossbeam-epoch 0.9.18 — RUSTSEC-2026-0204
  • h2 0.3.27 and 0.4.10 — RUSTSEC-2026-0258
  • quick-xml 0.32.0 — RUSTSEC-2026-0194 / RUSTSEC-2026-0195
  • quinn-proto 0.11.12 — RUSTSEC-2026-0037 / RUSTSEC-2026-0185
  • rkyv 0.7.45 — RUSTSEC-2026-0001 / RUSTSEC-2026-0235
  • rustls-webpki 0.103.3 — RUSTSEC-2026-0049 / 0098 / 0099 / 0104
  • time 0.3.41 — RUSTSEC-2026-0009
  • webbrowser 1.0.4 — RUSTSEC-2026-0257

Acceptance criteria

  • Reproduce the audit from a fresh isolated worktree based on current main and map every vulnerable package to its direct dependency owner and reachable runtime/build surface.
  • Upgrade the smallest compatible direct/transitive dependency set; split if Tauri-wide migration or more than one independently deployable subsystem is required.
  • cargo audit reports zero unhandled vulnerabilities. Any advisory that truly cannot be removed has a narrow checked-in policy, concrete reachability analysis, expiry/follow-up, and reviewer approval rather than a blanket ignore.
  • Bodhi release tests, clippy/fmt, Node assembly tests, and the full macOS/Linux/Windows build matrix pass at the exact reviewed head.
  • Reverify Lotus Next receipt/resource behavior and real sidecar assembly so dependency refresh does not regress [bodhi] feat: consume the verified Lotus Next package in desktop bundles #64.

Scope boundary

This is pre-existing dependency work discovered during #65 review. It must not change #65, expand the Lotus Next acceptance slice, or weaken any existing gate. Use its own claim, branch, isolated worktree, PR, and exact-head review.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:readyReady for an agent to pick uppriority:P1High — this sprinttype:choreMaintenance, deps, tooling

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions