diff --git a/.cargo/audit.toml b/.cargo/audit.toml new file mode 100644 index 000000000..e8a321e36 --- /dev/null +++ b/.cargo/audit.toml @@ -0,0 +1,23 @@ +# cargo-audit configuration for the Rust workspace. +# +# Path matters: cargo-audit reads `.cargo/audit.toml`, not a root-level +# `audit.toml`. A file at the repo root is silently ignored. +# +# The `audit` job in .github/workflows/rust.yml is a BLOCKING gate. It runs on +# every PR touching Rust and nightly on the schedule (the `rust-changes` job +# reports `rust=true` for `schedule`/`workflow_dispatch`, so a newly-disclosed +# advisory surfaces without anyone touching Rust code). +# +# It was `continue-on-error: true` until the change that added this file, which meant it reported findings +# nobody saw: RUSTSEC-2026-0258 (h2, unbounded empty DATA frames) sat in a green +# run. Anything ignored here has to be listed explicitly, with a reason. + +[advisories] +ignore = [ + # `paste` is unmaintained — an advisory of project status, not a + # vulnerability; there is no patched version to move to. It is transitive + # and unavoidable at our layer: tokenizers -> paste and rav1e -> paste, + # both reached via fastembed. Re-evaluate when tokenizers moves to + # `pastey` (the maintained drop-in fork). + "RUSTSEC-2024-0436", +] diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index e14ef49d1..ce9d173ea 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -224,8 +224,12 @@ jobs: uses: taiki-e/install-action@v2 with: tool: cargo-audit,cargo-deny - - name: cargo audit (soft-fail) - continue-on-error: true + # Blocking. Soft-failing this made it useless: RUSTSEC-2026-0258 (h2, + # unbounded empty DATA frames -> unbounded memory or a panic) was + # reported by this job for as long as it existed and never turned a run + # red, so nobody acted on it. Accepted advisories go in audit.toml with + # a written reason rather than being swallowed wholesale here. + - name: cargo audit run: cargo audit - name: cargo deny check licenses continue-on-error: true diff --git a/Cargo.lock b/Cargo.lock index bfe188254..fe0ddb991 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1209,9 +1209,9 @@ dependencies = [ [[package]] name = "crossbeam-epoch" -version = "0.9.18" +version = "0.9.20" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5b82ac4a3c2ca9c3460964f020e1402edd5753411d7737aa39c3714ad1b5420e" +checksum = "2d6914041f254d6e9176c01941b21115dcfb7089e55135a35411081bd106ef3f" dependencies = [ "crossbeam-utils", ] @@ -1805,9 +1805,9 @@ dependencies = [ [[package]] name = "h2" -version = "0.4.15" +version = "0.4.16" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "6cb093c84e8bd9b188d4c4a8cb6579fc016968d14c99882163cd3ff402a4f155" +checksum = "a9f37a958b41b3b19ee2707c06439c0e9e547e847223eb791ecb0cb821c65e27" dependencies = [ "atomic-waker", "bytes",