Skip to content

fix(deps): clear RUSTSEC-2026-0190 via anyhow lockfile bump - #56

Merged
forkwright merged 2 commits into
mainfrom
fix/rustsec-2026-07
Jul 16, 2026
Merged

fix(deps): clear RUSTSEC-2026-0190 via anyhow lockfile bump#56
forkwright merged 2 commits into
mainfrom
fix/rustsec-2026-07

Conversation

@forkwright

Copy link
Copy Markdown
Owner

Clears the cargo-audit failure (--deny unsound) red since 2026-07-14: anyhow 1.0.103 fixes RUSTSEC-2026-0190. Lockfile-only re-resolution within the locked koinon commit's tree; cargo-deny was already green (informational advisory below its default severity).

anyhow 1.0.102->1.0.103 (Error::downcast_mut unsoundness), transitive via
the koinon git dep's wit-bindgen chain. Lockfile-only; the git dep's
locked commit is unchanged.
… ignores
Baseline expires 2026-08-13 pending hamma#57 burn-down (expired non-empty
baseline fails the gate). deny.toml/.cargo/audit.toml ignores removed:
their four RUSTSEC entries justified against crates (bincode, paste,
tokenizers/syntect, logismos cache) that do not exist in hamma's lockfile
— copy-pasted config that would mask real future advisories. Orchestration
exception documents the branch's original main-worktree commit.
Gate-Passed: kanon 0.1.6 +stages:fmt,check,clippy,nextest,lint sha:4559b617405fcef73cc9e09555f8f8efbc52b4f6
@forkwright
forkwright merged commit 2423485 into mainJul 16, 2026
6 checks passed
@forkwright
forkwright deleted the fix/rustsec-2026-07 branch July 16, 2026 17:18
@github-actionsgithub-actionsBot mentioned this pull request Jul 16, 2026
forkwright pushed a commit that referenced this pull request Jul 28, 2026
🤖 I have created a release *beep* *boop*
---
<details><summary>0.2.0</summary>
## [0.2.0](v0.1.0...v0.2.0)
(2026-07-28)
### Features
* **_llm:** add T0 corpus per
[#667](https://github.com/forkwright/hamma/issues/667) /
[#673](https://github.com/forkwright/hamma/issues/673) fleet rollout
([#10](#10))
([0568f51](0568f51))
* **control:** instrument async control client entry points
([#37](#37))
([e80622f](e80622f)),
closes [#20](#20)
* **control:** support zstd map responses
([dd5ab90](dd5ab90))
* **dictyon:** add TCP/TLS connection, registration, and map streaming
([a311d8a](a311d8a))
* **dictyon:** control protocol types and map response parser
([dfc25c7](dfc25c7))
* **dictyon:** migrate tracing init to koinon
([e5a4260](e5a4260))
* **dictyon:** Noise IK handshake, key types, HTTP transport skeleton
([aafea4f](aafea4f))
* **dictyon:** trace wire noise transport phases
([#38](#38))
([2d80231](2d80231)),
closes [#20](#20)
### Bug Fixes
* **cargo:** track lockfile for pinned rust toolchain
([#30](#30))
([e6a2f01](e6a2f01)),
closes [#29](#29)
* **ci:** resolve cargo-deny + MSRV + binary smoke failures
([#13](#13))
([9bb4533](9bb4533))
* **ci:** waive gate attestation by PR author, not by github.actor
([#69](#69))
([764422e](764422e)),
closes [#68](#68)
* **control:** accept node id peer removals
([7debc6b](7debc6b))
* **control:** apply peer patch map deltas
([#33](#33))
([dfc3731](dfc3731))
* **core:** parse peer patch map fields
([0686a66](0686a66))
* **deps:** clear RUSTSEC-2026-0190 via anyhow lockfile bump
([#56](#56))
([2423485](2423485))
* **lint:** add non_exhaustive to public error enums, mark public-key
fields
([0355297](0355297))
* **lint:** mechanical wins — allow→expect, indexing/slicing, casts,
http→https
([9e339db](9e339db))
* **lint:** resolve clippy warnings in hamma-core and wire integration
test ([#42](#42))
([079ad5e](079ad5e))
* **lint:** suppress pub-visibility for library API surface
([6d54674](6d54674))
* **lint:** unblock kanon gate
([f93ff63](f93ff63))
* **release:** bump the internal hamma-core pin and Cargo.lock with the
release ([#71](#71))
([dfdfc35](dfdfc35)),
closes [#70](#70)
* resolve 1 lint violations via local
([#8](#8))
([0d4aa84](0d4aa84))
### Refactoring
* **dictyon:** replace expect with ? and rename test helper
([#9](#9))
([655b783](655b783))
* **lint:** split oversized modules; add hamma-core integration tests
([fa8f54f](fa8f54f))
* rename plegma→hamma, plegma-core→hamma-core
([a67f792](a67f792))
### Documentation
* add CLAUDE.md precedence preamble
(forge[#153](https://github.com/forkwright/hamma/issues/153))
([e91ebea](e91ebea))
* add CONTRIBUTING.md for 05e cutover
([#1](#1))
([9dd5f87](9dd5f87))
* add llms.txt per kanon doc standards (refs
[#10](#10))
([#11](#11))
([e869fe1](e869fe1))
* **agents:** add AGENTS.md per fleet repo-structure standard
([#40](#40))
([0382da1](0382da1))
* **hamma:** align pre-alpha status
([#6](#6))
([873a6c3](873a6c3))
* **hamma:** replace standards copy with kanon pointer
([#8](#8))
([324ff18](324ff18))
* sanitize local bootstrap docs
([4c57d40](4c57d40))
* **standards:** add canonical standards from kanon
([#1](#1))
([81e5007](81e5007))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@forkwright