Skip to content

fix: resolve active dependency advisories#22

Merged
OneNoted merged 1 commit into
mainfrom
dependabot-advisories
May 9, 2026
Merged

fix: resolve active dependency advisories#22
OneNoted merged 1 commit into
mainfrom
dependabot-advisories

Conversation

@OneNoted

@OneNoted OneNoted commented May 9, 2026

Copy link
Copy Markdown
Owner

Summary

  • Updates Cargo.lock to patched versions for the active Dependabot advisories.
  • Bumps rand from 0.9.2 to 0.9.3.
  • Bumps rustls-webpki from 0.103.10 to 0.103.13.

Validation

  • cargo check --locked
  • cargo test --locked
  • cargo audit

Update the lockfile to patched rand and rustls-webpki releases so GitHub security scanning no longer reports the active Dependabot alerts.

Constraint: Alerts are lockfile-only Rust dependency advisories from GitHub Dependabot.
Confidence: high
Scope-risk: narrow
Tested: cargo check --locked
Tested: cargo test --locked
Tested: cargo audit
Not-tested: GitHub Dependabot rescanning before PR merge
@OneNoted OneNoted merged commit 6eed396 into main May 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant