Repository navigation
Conversation
`event-listener` 5.4.1 allows `!Send` tags to cross thread boundaries via `StackSlot` (RUSTSEC-2026-0221, published 2026-07-13). It reaches the runtime-manager transitively through async-broadcast, so this is a lockfile-only change: no manifest edit, no API surface touched. Turned up when the vuln gate went red on an unrelated PR — the advisory database picked it up between this morning's runs and this afternoon's, so it now fails on master too. This clears RUSTSEC-2026-0221 only. `cargo audit` still reports RUSTSEC-2026-0222 (wasmtime 45.0.3, "Stores can mix up type indices between engines"), which is NOT fixable the same way: every patched line the advisory allows — 46.0.2+ and 47.0.3+ — pulls cranelift crates requiring Rust 1.94, while the repo pins 1.93 in rust-toolchain.toml, two CI workflows, and the service Dockerfiles. That is a cross-cutting toolchain decision and gets its own change rather than riding along here. Verified: cargo audit no longer reports 0221, release build clean.
🔎 Codex cross-audit (agent:audit)No Blocking findings. I found no correctness, security, or edge-case regressions introduced by this PR. The only change is Verification:
|
🔷 Gemini cross-audit (agent:audit-gemini)Based on an audit of the unified diff in 1. 🛑 Malformed
|
🛡️ Vuln scan — ❌ vulnerable dependency found |
|
Superseded by #209, which includes this exact commit as its base — the event-listener bump alone can't turn the |
Lockfile-only.
event-listener5.4.1 → 5.4.2, clearing RUSTSEC-2026-0221 (!Sendtags crossing thread boundaries viaStackSlot, published 2026-07-13). It reaches runtime-manager transitively viaasync-broadcast, so no manifest edit and no API surface touched.Turned up when the
vulngate went red on an unrelated PR — the advisory DB picked it up between this morning's runs and this afternoon's, so it fails onmastertoo.Not fixed here: RUSTSEC-2026-0222 (wasmtime)
cargo auditstill reports wasmtime 45.0.3 — "Stores can mix up type indices between engines". Every patched line the advisory allows (46.0.2+, 47.0.3+) pulls cranelift crates that require Rust 1.94, while the repo pins 1.93 inrust-toolchain.toml, two CI workflows, and the service Dockerfiles.That is a cross-cutting toolchain bump and needs its own decision — so
vulnstays red until it's made.Verification
cargo auditno longer reports 0221cargo build --releaseclean