Skip to content

fix: patch rustls and sharp security advisories - #922

Merged
leynier merged 2 commits into
mainfrom
fix/dependabot-security-alerts
Oct 7, 2026
Merged

leynier merged 2 commits into
mainfrom
fix/dependabot-security-alerts

Conversation

@leynier

@leynier leynier commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Summary

  • Bump transitive rustls from 0.23.43 to 0.23.45 in rust/Cargo.lock and cloud/Cargo.lock (GHSA-2mjx-qc3c-rqvc).
  • Bump landing sharp from 0.35.4 to 0.35.5, including its bundled libvips binaries (GHSA-wq5f-xc86-pv6w). The installed build reports librsvg 2.63.2.

Dependabot alerts 1-3 were already fixed. No documentation update: this does not change runtime behavior or contributor workflow.

Validation

  • cargo metadata --locked for rust/Cargo.toml and cloud/Cargo.toml with Rust 1.98.0 resolves rustls 0.23.45.
  • bun test in landing/ (103 pass) and bun run build.
  • Loaded sharp 0.35.5 reports rsvg 2.63.2.

Risks

  • The Rust crates were not recompiled. The bump stays inside the 0.23 range already used by reqwest, sqlx, and sentry.
  • sharp is a landing devDependency used to render demo media. The site build does not decode untrusted SVG.

Bump transitive rustls to 0.23.45 in the desktop and cloud lockfiles, and landing sharp to 0.35.5.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Reviewed the lockfile security bumps in 7ae9c061.

  • rustls 0.23.45: cloud/Cargo.lock and rust/Cargo.lock each move the only rustls pin from 0.23.43 to 0.23.45, the patched release for GHSA-2mjx-qc3c-rqvc. The published checksum matches, and the tightened rustls-webpki and aws-lc-rs floors are already satisfied by the locked versions.
  • sharp 0.35.5: landing/package.json and landing/bun.lock move the direct devDependency and its bundled @img/sharp-libvips-* 1.3.4 packages to the GHSA-wq5f-xc86-pv6w patched release, which ships librsvg 2.63.2. The npm integrity matches the published package.

Pullfrog  | View workflow run | Using grok-4.7 | 𝕏

A concurrent stale reclaim can return 503 while the other request still holds the claim. Count one successful delivery and treat 503 as valid, matching the earlier duplicate race.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Reviewed the contract-test change in 95f9f733 since the prior review of 7ae9c061.

  • Accepted in-progress on stale reclaim: The concurrent stale-pending reclaim now allows 503 when the loser observes the winner's fresh claim, instead of requiring both posts to return 200.
  • Kept the one-delivery invariant: concurrent_duplicate_deliveries still requires successful responses to be duplicates, queued deliveries to sum to 1, and the send counter to move by exactly one.

Pullfrog  | View workflow run | Using grok-4.7 | 𝕏

@leynier
leynier merged commit 8f0fe01 into main Oct 7, 2026
26 checks passed
@leynier
leynier deleted the fix/dependabot-security-alerts branch October 7, 2026 04:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant