Skip to content

chore(deps): refresh compatible dependencies - #170

Merged
mpiton merged 2 commits into
mainfrom
chore/dependency-upgrades
Jul 16, 2026
Merged

chore(deps): refresh compatible dependencies#170
mpiton merged 2 commits into
mainfrom
chore/dependency-upgrades

Conversation

@mpiton

@mpiton mpiton commented Jul 16, 2026

Copy link
Copy Markdown
Owner

Summary

  • refresh compatible npm and Rust dependencies
  • disable unused SeaORM defaults and remove the vulnerable rsa dependency
  • restore strict dependency policy now that Extism uses crates.io
  • regenerate Tauri capability schemas

Validation

  • npm audit: 0 vulnerabilities
  • frontend: 702 tests passed
  • Rust: 1,549 tests passed; cargo deny passed
  • Tauri release build produced deb, rpm, and AppImage bundles

Known issue

  • cargo audit still reports RUSTSEC-2026-0194 and RUSTSEC-2026-0195 through wayland-scanner 0.31.10; the upstream fix is merged but not released

Type

chore


Summary by cubic

Refresh compatible npm and Rust dependencies, tighten cargo-deny policy, and regenerate Tauri capability schemas to reduce attack surface and stay current. Drops unused DB drivers and the vulnerable rsa crate, and adds permissions for new Tauri commands.

  • Dependencies
    • Updated Rust and frontend deps (includes patched quinn-proto).
    • Set default-features = false for sea-orm/sea-orm-migration; removes MySQL/PostgreSQL drivers and rsa.
    • Tightened cargo-deny: wildcards set to deny; removed ring OpenSSL license exception; extism now from crates.io.
    • Regenerated schemas with new permissions: supports_multiple_windows, set_icon_with_as_template, activity_name, scene_identifier.
    • Validation: npm audit 0; 702 frontend + 1,549 Rust tests passed; cargo deny passed; Tauri release bundles built.
    • Known issue: cargo audit still flags RUSTSEC-2026-0194/0195 via wayland-scanner 0.31.10; upstream fix pending.

Written for commit fbc6b10. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Security
    • Updated compatible dependencies to address known vulnerabilities and improve overall hardening.
    • Disabled unused default features for database migrations to avoid pulling in unnecessary database drivers.
    • Tightened dependency policy checks by strengthening wildcard handling and refreshing the security advisory exceptions/ignore rationale.
    • Clarified security advisory coverage related to XML parsing behavior and noted remaining audit exceptions until upstream fixes land.

@qodo-code-review

Copy link
Copy Markdown

Qodo reviews are paused for this user.

Troubleshooting steps vary by plan Learn more →

On a Teams plan?
Reviews resume once this user has a paid seat and their Git account is linked in Qodo.
Link Git account →

Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center?
These require an Enterprise plan - Contact us
Contact us →

@github-actions github-actions Bot added documentation Improvements or additions to documentation dependencies configuration labels Jul 16, 2026
@coderabbitai

coderabbitai Bot commented Jul 16, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

SeaORM default features were disabled, cargo-deny advisory policies were revised, wildcard dependencies now fail validation, and the security changes were recorded in the changelog.

Changes

Security hardening

Layer / File(s) Summary
Disable unused SeaORM defaults
src-tauri/Cargo.toml
SeaORM dependencies now disable Cargo default features.
Tighten cargo-deny policies and document audit status
deny.toml, CHANGELOG.md
RustSec advisory entries and rationales were updated, wildcard bans now deny violations, and remaining audit findings were documented.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • mpiton/vortex#167: Modifies the same RustSec advisory ignore configuration in deny.toml.

Suggested labels: rust

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the dependency refresh and hardening work in this pull request.

Comment @coderabbitai help to get the list of available commands.

@socket-security

socket-security Bot commented Jul 16, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​tokio@​1.52.2 ⏵ 1.52.35810093100100
Updatednpm/​@​tanstack/​react-virtual@​3.13.23 ⏵ 3.14.610010069 +396 -1100
Updatednpm/​@​radix-ui/​react-slot@​1.2.4 ⏵ 1.3.0100 +110069 +195100
Updatednpm/​@​types/​react@​19.2.14 ⏵ 19.2.171001007992100
Updatednpm/​vitest@​4.1.3 ⏵ 4.1.1098 +110079 +198 +1100
Updatednpm/​@​vitest/​coverage-v8@​4.1.3 ⏵ 4.1.10991007999 +2100
Updatednpm/​recharts@​3.8.1 ⏵ 3.9.279 +1100100 +295100
Updatedcargo/​libc@​0.2.184 ⏵ 0.2.1868010093100100
Updatedcargo/​reqwest@​0.13.2 ⏵ 0.13.480 +210093100100
Updatednpm/​lucide-react@​1.7.0 ⏵ 1.24.0100 +110098 +296 +280
Updatednpm/​radix-ui@​1.4.3 ⏵ 1.6.297 +11008198 +1100
Updatednpm/​jsdom@​29.0.2 ⏵ 29.1.181100100 +190100
Updatednpm/​@​types/​node@​25.5.2 ⏵ 25.9.51001008196 +2100
Updatedcargo/​tauri@​2.10.3 ⏵ 2.11.581 +1100 +2100100100
Updatedcargo/​serde_json@​1.0.149 ⏵ 1.0.1508210093100100
Updatednpm/​tailwindcss@​4.2.2 ⏵ 4.3.21001008498100
Updatednpm/​react@​19.2.4 ⏵ 19.2.71001008497100
Updatedcargo/​codspeed-criterion-compat@​4.6.0 ⏵ 4.7.08610098100100
Updatednpm/​tailwind-merge@​3.5.0 ⏵ 3.6.0100 +110086 +196100
Updatednpm/​@​tanstack/​react-query@​5.97.0 ⏵ 5.101.2991008897 -1100
Updatednpm/​@​tauri-apps/​cli@​2.10.1 ⏵ 2.11.49510088 +198 +2100
Updatednpm/​zustand@​5.0.12 ⏵ 5.0.1410010010089 -1100
Updatednpm/​@​tauri-apps/​api@​2.10.1 ⏵ 2.11.1100 +110089 +193100
Updatednpm/​@​tauri-apps/​plugin-dialog@​2.7.0 ⏵ 2.7.110010010090 -1100
Updatednpm/​@​tailwindcss/​vite@​4.2.2 ⏵ 4.3.2100 +110090 +198100
Updatedcargo/​tauri-plugin-dialog@​2.7.0 ⏵ 2.7.190 +1100100100100
Updatednpm/​i18next@​26.0.4 ⏵ 26.3.61001009297 +1100
Updatednpm/​lefthook@​2.1.5 ⏵ 2.1.1092 +110010093 +1100
Updatednpm/​oxlint@​1.59.0 ⏵ 1.74.099 +110092 +196 +1100
Updatednpm/​react-dom@​19.2.4 ⏵ 19.2.71001009298100
Updatedcargo/​bytes@​1.11.1 ⏵ 1.12.110010093100100
Updatedcargo/​dashmap@​6.1.0 ⏵ 6.2.110010093100100
Updatedcargo/​digest@​0.11.2 ⏵ 0.11.310010093100100
See 8 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Jul 16, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: src-tauri/Cargo.lockcargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: cargo openssl is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?cargo/sea-orm-migration@1.1.20cargo/sea-orm@1.1.20cargo/openssl@0.10.81

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/openssl@0.10.81. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: src-tauri/Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: cargo zerocopy is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?cargo/codspeed-criterion-compat@4.7.0cargo/extism@1.30.0cargo/tauri@2.11.5cargo/tauri-plugin-notification@2.3.3cargo/tauri-plugin-clipboard-manager@2.3.2cargo/zerocopy@0.8.54

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/zerocopy@0.8.54. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/@tailwindcss/vite@4.3.2npm/knip@6.27.0npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/jsdom@29.1.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@29.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.jsonnpm/jsdom@29.1.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@29.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@coderabbitai coderabbitai Bot added the rust label Jul 16, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@CHANGELOG.md`:
- Around line 12-15: Update the Security entry in CHANGELOG.md to document that
cargo-audit still reports RUSTSEC-2026-0194 and RUSTSEC-2026-0195 through
wayland-scanner 0.31.10, and state that these findings are accepted risks
pending removal once an upstream fix is available.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 191fcfe5-16f7-48fc-a1ce-3ceee4a22c32

📥 Commits

Reviewing files that changed from the base of the PR and between d780e0f and fc30337.

⛔ Files ignored due to path filters (5)
  • package-lock.json is excluded by !**/package-lock.json
  • src-tauri/Cargo.lock is excluded by !**/*.lock
  • src-tauri/gen/schemas/acl-manifests.json is excluded by !**/gen/**
  • src-tauri/gen/schemas/desktop-schema.json is excluded by !**/gen/**
  • src-tauri/gen/schemas/linux-schema.json is excluded by !**/gen/**
📒 Files selected for processing (3)
  • CHANGELOG.md
  • deny.toml
  • src-tauri/Cargo.toml

Comment thread CHANGELOG.md

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 8 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread deny.toml Outdated
@codspeed-hq

codspeed-hq Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

⚡ 2 improved benchmarks
❌ 5 regressed benchmarks
✅ 19 untouched benchmarks

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Benchmark BASE HEAD Efficiency
reject_invalid 464.4 ns 610.3 ns -23.9%
full_lifecycle 230.6 ns 288.9 ns -20.19%
split 413.6 ns 501.1 ns -17.46%
detect_md5 628.3 ns 745 ns -15.66%
detect_sha256 763.6 ns 851.1 ns -10.28%
normalize_max_concurrent 179.2 ns 150 ns +19.44%
create_valid 281.4 ns 252.2 ns +11.56%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing chore/dependency-upgrades (fbc6b10) with main (d780e0f)

Open in CodSpeed

@mpiton
mpiton merged commit 5b55d38 into main Jul 16, 2026
16 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

configuration dependencies documentation Improvements or additions to documentation rust

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant