Commit 0aa24b7
security(deps): lockfile bumps clearing open Cargo advisories (Track E)
Lockfile-only (cargo update -p; Cargo.toml untouched):
openssl 0.10.76 -> 0.10.80 (clears GHSA-8c75/ghm9/hppc/phqj/pqf5/xmgf/xp3w/xv59)
rand 0.9.2 -> 0.9.3 (RUSTSEC-2026-0097 / GHSA-cq8v-f236-94qc)
thin-vec 0.2.14 -> 0.2.16 (RUSTSEC-2026-0103 / GHSA-xphw-cqx3-667j)
Clears the live Dependabot Rust advisories on this repo (docmatrix#21, Track E).
Same recipe as 007 #44. Residual RUSTSEC unmaintained-crate advisories
(ansi_term/yaml-rust/bincode/rustls-pemfile) are NOT vulnerabilities and need
dep removal/replacement separately.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent b9ed515 commit 0aa24b7
1 file changed
Lines changed: 8 additions & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments