Skip to content

fix(deps): security updates#201

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/dep-security-updates
Jun 25, 2026
Merged

fix(deps): security updates#201
hyperpolymath merged 1 commit into
mainfrom
fix/dep-security-updates

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Dependabot Rust security remediation (personal-sysadmin/Cargo.lock)

Fixed

  • rand: 0.9.2 -> 0.9.3 (low severity advisory; patched in-range via cargo update).

Flagged — not auto-fixable

  • hickory-proto (medium, patched 0.26.1): blocked. Current 0.25.2 is locked by libp2p-mdns 0.48.0 -> libp2p 0.56.0, whose requirement is ^0.25.2. The patched 0.26.1 is a MAJOR bump outside the range, so cargo update cannot reach it without a manifest major upgrade of libp2p. needs-manual-major (0.25.2 -> 0.26.1).
  • hickory-proto (high, patched NONE): no-patch-available — no fixed version exists upstream for this advisory. Updating to 0.26.1 (even if libp2p were bumped) is not guaranteed to address it.

No Cargo.toml or checksum hand-edits were made. Do not merge until reviewed.

@hyperpolymath hyperpolymath merged commit 8b34d38 into main Jun 25, 2026
11 of 14 checks passed
@hyperpolymath hyperpolymath deleted the fix/dep-security-updates branch June 25, 2026 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant