Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,8 @@ jobs:
sudo apt-get update
sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: 1.98.1
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
workspaces: ./src-tauri -> target
Expand Down Expand Up @@ -64,6 +66,7 @@ jobs:
- run: corepack enable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: 1.98.1
targets: ${{ matrix.target }}
components: rustfmt, clippy
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,8 @@ jobs:
sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
if: matrix.language == 'rust'
with:
toolchain: 1.98.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
if: matrix.language == 'rust'
with:
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ and then you can start the Tauri dev server:
yarn run tauri dev
```

Use Node.js 24 LTS, Yarn 4.18.0 (pinned in `package.json`), and Rust with the native Tauri prerequisites.
Use Node.js 24 LTS, Yarn 4.18.0 (pinned in `package.json`), and Rust 1.98.1 (pinned in `rust-toolchain.toml`) with the native Tauri prerequisites.
https://v2.tauri.app/start/prerequisites/

Enable the pinned Yarn version through Corepack:
Expand Down
29 changes: 29 additions & 0 deletions docs/dependencies.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Dependency maintenance

Update `@tauri-apps/api` and the Rust `tauri` crate together on the same minor
release. Keep the JavaScript and Rust clipboard plugins on the same exact version.
Commit both lockfiles and use immutable/locked installs in CI. Avoid prereleases
and dependency overrides that bypass upstream compatibility requirements.

Rust 1.98.1 is pinned in `rust-toolchain.toml` and the CI toolchain inputs. Update
both when changing the compiler so local builds, benchmarks and CodeQL agree.

## Audit after the September 2026 update

`yarn npm audit --all --recursive` reports no advisories. `cargo audit` reports no
entries in its vulnerability list, but retains these upstream warnings:

| Crates | Advisory | Status |
| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| `glib` 0.18.5 | [RUSTSEC-2024-0429](https://rustsec.org/advisories/RUSTSEC-2024-0429.html) | Unsound iterator implementation in the GTK dependency line used by Tauri; the application does not directly call this iterator. |
| `proc-macro-error` 1.0.4 | [RUSTSEC-2024-0370](https://rustsec.org/advisories/RUSTSEC-2024-0370.html) | Unmaintained transitive dependency. |
| `unic-char-property`, `unic-char-range`, `unic-common`, `unic-ucd-ident`, `unic-ucd-version` | RUSTSEC-2025-0081, 0075, 0080, 0100, 0098 | Unmaintained transitive dependencies. |

These warnings are not suppressed. Recheck upstream Tauri/GTK compatibility on
future upgrades; forcing a different GTK/GLib major is not a compatible lockfile
update. A clean vulnerability count is not a claim that all dependencies are
maintained or free of soundness issues.

The update removes the previously reported `quick-xml` vulnerabilities, the
`anyhow` and `rand` soundness warnings, and yanked versions. Repeat both audits
before publishing because advisory data changes independently of the lockfiles.
6 changes: 3 additions & 3 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,9 @@
"@eslint/js": "^10.0.1",
"@fortawesome/free-solid-svg-icons": "^7.3.1",
"@sveltejs/vite-plugin-svelte": "^7.3.0",
"@tauri-apps/api": "~2.10.1",
"@tauri-apps/cli": "~2.10.0",
"@tauri-apps/plugin-clipboard-manager": "~2.3.2",
"@tauri-apps/api": "~2.11.1",
"@tauri-apps/cli": "~2.11.4",
"@tauri-apps/plugin-clipboard-manager": "2.3.3",
"@tsconfig/svelte": "^5.0.8",
"@types/dygraphs": "^2.1.11",
"codemirror": "^6.0.2",
Expand Down
4 changes: 4 additions & 0 deletions rust-toolchain.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
[toolchain]
channel = "1.98.1"
profile = "minimal"
components = ["rustfmt", "clippy"]
Loading
Loading