fix: clear the pyo3 advisories with pyo3 0.29.2 - #30
Merged
Merged
Conversation
pyo3 0.22.6 had three open advisories. 0.29.2 is the newest release and clears all three: - GHSA-36hh-v3qg-5jq4 / RUSTSEC-2026-0176 (high), fixed in 0.29.0 - GHSA-chgr-c6px-7xpp / RUSTSEC-2026-0177 (medium), fixed in 0.29.0 - GHSA-pph8-gcv7-4qj5 / RUSTSEC-2025-0020 (low), fixed in 0.24.1 The bindings move to the current API: Py<PyAny> for PyObject, Python::attach for with_gil, PyDict::new and py.import for the _bound forms, into_py_any for into_py. VrlResult opts out of the FromPyObject derive, which nothing uses. The crate-level lint allow for pyo3 0.22's macro expansion goes, and so do the deny.toml and osv-scanner.toml ignores for two advisories that no longer match anything. Three more security patch releases ride along in the lockfiles: - domain 0.12.2 -> 0.12.3 (RUSTSEC-2026-0310), built into the published wheel through vrl - rustls 0.23.43 -> 0.23.45 (RUSTSEC-2026-0285), full-stdlib builds only - urllib3 2.7.0 -> 2.8.0 in build/uv.lock (CVE-2026-97687, CVE-2026-97689), which fails pip-audit in the build/ quality job The docs that described pyo3 0.22's 3.13 interpreter ceiling lose those lines.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears the three open Dependabot alerts on pyo3 by moving vector-bindings from 0.22.6 to 0.29.2, the newest release (crates.io, 2026-08-05).
The API move is all in
src/lib.rsand it is mechanical:Py<PyAny>forPyObject,Python::attachforwith_gil,PyDict::new/py.importfor the_boundforms,into_py_anyforinto_py.VrlResulttakesskip_from_py_objectbecause nothing extracts it from Python. The crate-level#![allow(unsafe_op_in_unsafe_fn, clippy::useless_conversion)]that only existed for pyo3 0.22's macro expansion is gone, and clippy stays clean without it. No Python-visible change and no Python floor change --abi3-py312stays.The deny.toml ignores for RUSTSEC-2025-0020 and RUSTSEC-2026-0177 go too. With them left in, cargo deny warns
advisory-not-detectedon both.osv-scanner.tomlonly carried those two, so it is deleted.Also along for the ride, both security patch releases in
vector-bindings/Cargo.lock:The
build/uv.lockhunk (urllib3 2.7.0 -> 2.8.0) is now a no-op. #29 landed the same bump on main while this was open, andgit diff origin/main HEAD -- build/uv.lockis empty, so the squash merge adds nothing there. The commit message still mentions it.Three doc lines that described pyo3 0.22's 3.13 ceiling are gone.
CI on ad256be: Commit messages, vector-vrl + build/ (quality + test) and vector-bindings (quality + test) all pass. Plan set
run-build=falseon the PR, so the wheel legs did not run here.Run locally in a clean worktree off main:
make quality-rust-- fmt, clippy src + tests, cargo deny, cargo audit, osv-scanner and the feature matrix all passmake test-rust-- 38/38 default, 39/39 full-stdlibmake quality-pythonandmake test-python-- pass, 1045 tests in vector-vrl with 0 skipped, run against an extension built from pyo3 0.29.2maturin build --release--vector_vrl-1.0.5-cp312-abi3-manylinux_2_39_x86_64.whl. Thewheel_smoke_check.pyhero script passes against it in a 3.14 venv.Heads up for the next publish, not this PR:
build/wheel_smoke_check.pyas it stands on main makes a 3.12 venv from thecp312tag.requires-pythonhas been>=3.14since #26, so uv refuses the install. Reproduced locally against this wheel, and main's run 35810804378 failed at that step. #27 is the fix.NOT verified: aarch64 and macOS wheels, and the manylinux container build.
Done when this merges and Dependabot closes alerts 17, 18 and 19.