Skip to content

Bump version and security lockfile updates - #33

Merged
tripledoublev merged 1 commit into
mainfrom
chore/dependabot-security-lockfile
May 15, 2026
Merged

tripledoublev merged 1 commit into
mainfrom
chore/dependabot-security-lockfile

Conversation

@tripledoublev

Copy link
Copy Markdown
Collaborator

Summary

  • bump save-dweb-backend to 0.3.6
  • update Cargo.lock for resolvable Dependabot security alerts: rand 0.8.x, rand 0.9.x, quinn-proto, and rustls-webpki 0.103.x
  • leave unresolved transitive alerts blocked by current Veilid/Iroh compatibility constraints

Notes

The remaining hickory-proto, older rustls-webpki, and lru alerts cannot be cleanly resolved with a lockfile-only update. Cargo rejects the patched versions because the current graph is constrained by veilid-core/veilid-tools and the patched Iroh fork used to keep Veilid and Iroh compatible.

Verification

  • cargo check

@tripledoublev
tripledoublev merged commit 1c0c3fa into main May 15, 2026
1 check passed
@tripledoublev
tripledoublev deleted the chore/dependabot-security-lockfile branch May 15, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant