Skip to content

fix: clear the pyo3 advisories with pyo3 0.29.2 - #30

Merged
catinspace-au merged 1 commit into
mainfrom
fix/pyo3-advisories
Sep 30, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/pyo3-advisories

Conversation

@catinspace-au

@catinspace-au catinspace-au commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Clears the three open Dependabot alerts on pyo3 by moving vector-bindings from 0.22.6 to 0.29.2, the newest release (crates.io, 2026-08-05).

The API move is all in src/lib.rs and it is mechanical: Py<PyAny> for PyObject, Python::attach for with_gil, PyDict::new / py.import for the _bound forms, into_py_any for into_py. VrlResult takes skip_from_py_object because nothing extracts it from Python. The crate-level #![allow(unsafe_op_in_unsafe_fn, clippy::useless_conversion)] that only existed for pyo3 0.22's macro expansion is gone, and clippy stays clean without it. No Python-visible change and no Python floor change -- abi3-py312 stays.

The deny.toml ignores for RUSTSEC-2025-0020 and RUSTSEC-2026-0177 go too. With them left in, cargo deny warns advisory-not-detected on both. osv-scanner.toml only carried those two, so it is deleted.

Also along for the ride, both security patch releases in vector-bindings/Cargo.lock:

  • domain 0.12.2 -> 0.12.3 (RUSTSEC-2026-0310), built into the published wheel through vrl
  • rustls 0.23.43 -> 0.23.45 (RUSTSEC-2026-0285), full-stdlib builds only

The build/uv.lock hunk (urllib3 2.7.0 -> 2.8.0) is now a no-op. #29 landed the same bump on main while this was open, and git diff origin/main HEAD -- build/uv.lock is empty, so the squash merge adds nothing there. The commit message still mentions it.

Three doc lines that described pyo3 0.22's 3.13 ceiling are gone.

CI on ad256be: Commit messages, vector-vrl + build/ (quality + test) and vector-bindings (quality + test) all pass. Plan set run-build=false on the PR, so the wheel legs did not run here.

Run locally in a clean worktree off main:

  • make quality-rust -- fmt, clippy src + tests, cargo deny, cargo audit, osv-scanner and the feature matrix all pass
  • make test-rust -- 38/38 default, 39/39 full-stdlib
  • make quality-python and make test-python -- pass, 1045 tests in vector-vrl with 0 skipped, run against an extension built from pyo3 0.29.2
  • maturin build --release -- vector_vrl-1.0.5-cp312-abi3-manylinux_2_39_x86_64.whl. The wheel_smoke_check.py hero script passes against it in a 3.14 venv.

Heads up for the next publish, not this PR: build/wheel_smoke_check.py as it stands on main makes a 3.12 venv from the cp312 tag. requires-python has been >=3.14 since #26, so uv refuses the install. Reproduced locally against this wheel, and main's run 35810804378 failed at that step. #27 is the fix.

NOT verified: aarch64 and macOS wheels, and the manylinux container build.

Done when this merges and Dependabot closes alerts 17, 18 and 19.

pyo3 0.22.6 had three open advisories. 0.29.2 is the newest release and clears all three:

- GHSA-36hh-v3qg-5jq4 / RUSTSEC-2026-0176 (high), fixed in 0.29.0
- GHSA-chgr-c6px-7xpp / RUSTSEC-2026-0177 (medium), fixed in 0.29.0
- GHSA-pph8-gcv7-4qj5 / RUSTSEC-2025-0020 (low), fixed in 0.24.1

The bindings move to the current API: Py<PyAny> for PyObject, Python::attach for with_gil, PyDict::new and py.import for the _bound forms, into_py_any for into_py. VrlResult opts out of the FromPyObject derive, which nothing uses. The crate-level lint allow for pyo3 0.22's macro expansion goes, and so do the deny.toml and osv-scanner.toml ignores for two advisories that no longer match anything.

Three more security patch releases ride along in the lockfiles:

- domain 0.12.2 -> 0.12.3 (RUSTSEC-2026-0310), built into the published wheel through vrl
- rustls 0.23.43 -> 0.23.45 (RUSTSEC-2026-0285), full-stdlib builds only
- urllib3 2.7.0 -> 2.8.0 in build/uv.lock (CVE-2026-97687, CVE-2026-97689), which fails pip-audit in the build/ quality job

The docs that described pyo3 0.22's 3.13 interpreter ceiling lose those lines.
@catinspace-au
catinspace-au merged commit 15d3bdd into main Sep 30, 2026
16 checks passed
@catinspace-au
catinspace-au deleted the fix/pyo3-advisories branch September 30, 2026 15:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant