chore(deps): bump rand from 0.8.5 to 0.10.2 - #409
Conversation
a5e76f0 to
39fdc8c
Compare
Bumps [rand](https://github.com/rust-random/rand) from 0.8.5 to 0.10.2. - [Release notes](https://github.com/rust-random/rand/releases) - [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md) - [Commits](rust-random/rand@0.8.5...0.10.2) --- updated-dependencies: - dependency-name: rand dependency-version: 0.10.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
39fdc8c to
16a80e1
Compare
|
Closing in favour of a combined security PR, because this proposes the wrong target version.
But the advisory this addresses (GHSA-cq8v-f236-94qc, low) is: 0.8.6 is a patch release. This PR jumps to (For the record: the Superseded by #436, which bumps |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Clears **all 12 open Dependabot advisories** in one change. Supersedes #397, #380 and #409. ## Changes | Package | Was | Now | Alerts cleared | |---|---|---|---| | `openssl` | 0.10.73 | **0.10.81** | 8 — 5 high, 2 medium, 1 low | | `openssl-sys` | 0.9.109 | 0.9.117 | (transitive) | | `rustls-webpki` | 0.103.10 | **0.103.15** | 3 — 1 high, 2 low | | `rand` | 0.8.5 | **0.8.8** | 1 — low | Each alert was checked against its own patched version; all 12 verify as cleared. `openssl` and `rustls-webpki` land *newer* than the superseded PRs proposed (0.10.80 / 0.103.13). Three files, and the lockfile moves exactly four package versions — no transitive churn. ## Why not `rand` 0.10.2, as #409 proposed `rand` is the only one of the three that reaches shipped code — it is a **runtime** dependency of the published `ic-vetkeys` crate (plus `ic-vetkeys-test-utils`, `ic-vetkeys-manager-canister`, `ic-vetkeys-canisters-tests`). But the advisory ([GHSA-cq8v-f236-94qc](GHSA-cq8v-f236-94qc), **low**) is: ``` vulnerable range: >= 0.7.0, < 0.8.6 first patched: 0.8.6 ``` 0.8.6 is a **patch** release. #409 proposed `0.10.2` — two breaking majors past the fix — which would force a `rand` 0.8 → 0.10 API migration across four crates including the published crypto crate, plus a lockstep `rand_chacha` 0.3 → 0.10 move. That is a large, risky change to absorb for a low-severity advisory that a patch bump resolves. This PR moves the manifest floor to `0.8.6` and the lock resolves `0.8.8`. (The `rand 0.10.2` already in `Cargo.lock` is unrelated — it arrives via `quinn-proto`, transitively under the dev-only `reqwest`, and is untouched here.) ## Severity in context `openssl` and `rustls-webpki` account for 11 of the 12 alerts, including all 6 highs — but their real exposure is **CI-only**. Both reach the tree solely via `reqwest`, which sits under `[dev-dependencies]` next to `pocket-ic`, and the canisters compile to `wasm32-unknown-unknown` where neither can exist. Neither appears in the published crate's dependency list: ``` rand req=^0.8.5 kind=normal rand_chacha req=^0.3.1 kind=normal pocket-ic req=^15.0.0 kind=dev ``` GitHub reports `scope=runtime` for all of them, but that is inferred from `Cargo.lock`, which carries no dev/runtime split for transitive packages. The manifests are the authority here. ## No release required Published `ic-vetkeys@0.9.0` declares `rand = "^0.8.5"` — i.e. `>=0.8.5, <0.9.0`. **`0.8.8` already satisfies that**, so anyone building against 0.9.0 today resolves the fixed version automatically; nobody is pinned to the vulnerable 0.8.5 except via a stale local lockfile, which `cargo update -p rand` fixes without any action from us. `Cargo.lock` is not consumed by dependents of a library crate, and dev-dependencies never propagate — so the `openssl` / `rustls-webpki` half has zero consumer impact by construction. The manifest floor bump to `0.8.6` only takes effect when we next publish, and is belt-and-braces for the stale-lockfile case. **It can ride the next release rather than triggering one.** Nothing here affects `@icp-sdk/vetkeys` (npm) or the Motoko package. ## Verification Ran the backend CI commands verbatim: - `cargo build --release --target wasm32-unknown-unknown` for all four canister crates — **pass** - `cargo test` — **14 passed, 0 failed**, including the pocket-ic integration tests (`key_sharing_should_work`, `should_preserve_state_across_upgrade`, `should_get_accessible_shared_key_ids`, …) that exercise the crypto paths using `rand` - `cargo test --doc` — pass (the 4 `ignored` doc-tests carry pre-existing `ignore` annotations, unchanged here) - `cargo clippy -- -Dwarnings` — pass - `cargo fmt --check` — pass `rand` 0.8.5 → 0.8.8 is a patch bump inside 0.8, so no API change was expected; the green build and integration tests confirm it rather than assume it. ## Superseded - #397 — `openssl` → 0.10.80. Included here at 0.10.81. - #380 — `rustls-webpki` → 0.103.13. Included here at 0.103.15. - #409 — `rand` → 0.10.2. Replaced with the 0.8.x patch fix, per above. Also closed as obsolete while triaging: #337, #316, #315 (targeted `examples/`, removed in #377) and #406 (`vite` 7.3.5, already superseded by `^7.3.6` from #434). 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps rand from 0.8.5 to 0.10.2.
Changelog
Sourced from rand's changelog.
... (truncated)
Commits
1540ea3Prepare rand 0.10.2 (#1800)a29964aBump chacha20 from 0.10.0 to 0.10.1 in the all-deps group (#1801)ced9491Tweak docs for RngExt::random_range and SampleRange (#1798)db14664Check UniformChar validity on deser (#1790)bea8620Bump the all-deps group with 2 updates (#1796)4f44932Bump actions/cache from 5 to 6 (#1795)b999a13Bump actions/checkout from 6 to 7 (#1794)aeab810Avoid unsafe where safety depends on non-local values (#1791)1896d7cAdd typos CI job (#1789)43eddeeBump the all-deps group with 2 updates (#1788)