Skip to content

fix(deps): resolve 7 Dependabot security alerts (rand, aws-sdk) - #14

Merged
TheStreamCode merged 1 commit into
mainfrom
fix/security-cargo-updates
Sep 23, 2026
Merged

TheStreamCode merged 1 commit into
mainfrom
fix/security-cargo-updates

Conversation

@TheStreamCode

Copy link
Copy Markdown
Owner

Dependabot updater reported security_update_not_possible on all 4 security jobs (rand, aws-sdk-sso, aws-sdk-ssooidc, aws-sdk-sts). Fixed manually, lockfile-only, no manifest changes.

  • rand 0.8.5 to 0.8.8, 0.9.2 to 0.9.5, 0.10.0 to 0.10.3 (unsound custom-logger advisory, first_patched 0.8.6/0.9.3/0.10.1)
  • aws-sdk-s3 1.109.0 to 1.122.0, sso 1.86.0 to 1.93.0, ssooidc 1.89.0 to 1.95.0, sts 1.88.0 to 1.97.0 (GHSA-g59m-gf8j-gjf5, all past first_patched)

Closes Dependabot alerts #2-#7, #11.

- rand 0.8.5->0.8.8, 0.9.2->0.9.5, 0.10.0->0.10.3 (unsound custom-logger advisory)
- aws-sdk-s3/sso/ssooidc/sts past first_patched for GHSA-g59m-gf8j-gjf5
- lockfile-only, no manifest changes; Dependabot updater reported
  security_update_not_possible, fixed manually
@TheStreamCode
TheStreamCode merged commit fd79315 into main Sep 23, 2026
10 checks passed
@TheStreamCode
TheStreamCode deleted the fix/security-cargo-updates branch September 23, 2026 13:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant