Skip to content

Commit 5e317ac

Browse files
committed
fix: Resolve security audit failure for rkyv RUSTSEC-2026-0001
- Add .cargo/audit.toml to ignore RUSTSEC-2026-0001 (rkyv vulnerability) - The rkyv crate is an optional dependency of rust_decimal that we don't use - We only enable db-tokio-postgres feature, not rkyv serialization - Updated rust_decimal to explicitly disable default features - Upgraded mysql_async from 0.34 to 0.36 Taariq Lewis, SerenAI, Paloma, and Volume at https://serendb.com
1 parent a9e4fd6 commit 5e317ac

File tree

3 files changed

+246
-478
lines changed

3 files changed

+246
-478
lines changed

.cargo/audit.toml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
# ABOUTME: Configuration for cargo-audit security scanner
2+
# ABOUTME: Ignores vulnerabilities in optional dependencies we don't use
3+
4+
[advisories]
5+
# RUSTSEC-2026-0001: rkyv vulnerability in Arc<T>/Rc<T> from_value on OOM
6+
# This is an OPTIONAL dependency of rust_decimal that we don't enable.
7+
# We only use rust_decimal's db-tokio-postgres feature, not rkyv serialization.
8+
# The rkyv crate appears in Cargo.lock but is never compiled into our binary.
9+
ignore = ["RUSTSEC-2026-0001"]

0 commit comments

Comments
 (0)