chore(deps): bump h2 to 0.4.17 for RUSTSEC-2026-0258 - #11378
michaelneale wants to merge 1 commit into
Conversation
The `deny` job has been failing on `main` and on every branch for at
least the last 12 runs of cargo-deny.yml:
error[vulnerability]: h2 unbounded empty DATA frames
Cargo.lock:415 h2 0.4.15
RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h: h2 accepted and queued empty
DATA frames without limit, so an undrained stream could grow memory
without bound or panic on length overflow. Low severity, patched in
0.4.16.
h2 is transitive only (hyper -> axum / reqwest / tonic / rmcp), so this
is a lock-file-only change. Hand-edited to the single h2 entry rather
than `cargo update -p h2`, which also churned 13 unrelated windows-sys
pins backwards.
Verified with the repo-pinned 1.96.1 toolchain:
cargo metadata --locked - lock file is consistent
cargo check --locked -p goose-cli - builds
Co-authored-by: Michael Neale <14976+michaelneale@users.noreply.github.com>
Signed-off-by: Michael Neale <14976+michaelneale@users.noreply.github.com>
|
Closing as redundant — superseded by #11207, which I should have found before opening this. #11207 ( I checked out #11207's head ( 0.4.16 clears RUSTSEC-2026-0258; the 0.4.17 in this PR was not required. #11207 is approved (filipkujawa) and green on all 18 checks, so the right move is to merge that rather than land a competing lock edit and hand it a conflict. Reopening this is one command if #11207 stalls. |
The
denygate is red for everyonecargo-deny.ymlhas failed on every one of its last 12 runs, including runs onmainitself:Same cause every time:
A gate that is red on every PR is signalling nothing — nobody can tell a real new advisory from the standing failure. That is the actual cost here; the advisory itself is Low severity.
The change
Lock-file only, two lines.
h2is transitive (hyper→axum/reqwest/tonic/rmcp/wiremock), so no manifest change is needed.I hand-edited the single
h2entry rather than runningcargo update -p h2, because that command also rewound 13 unrelatedwindows-syspins from 0.61.2 back to 0.52.0/0.59.0/0.60.2 — 30 lines of churn with nothing to do with this advisory, and a real risk on the Windows build.Verification (repo-pinned 1.96.1 from
rust-toolchain.toml)cargo metadata --locked— passes, so the hand-edit leaves a self-consistent lock filecargo check --locked -p goose-cli— builds cleanNot fixed here
The same
denyrun emits twoadvisory-not-detectedwarnings forRUSTSEC-2026-0194andRUSTSEC-2026-0195(deny.toml:17-18) — quick-xml ignores that no longer match any crate. They are warnings, not the failure, and pruning them is a separate call for whoever owns the dep. Left alone deliberately.Found while triaging #10515, whose only failing check was this.