chore: telegram lock file - #1853
Conversation
There was a problem hiding this comment.
Code Review
This pull request updates the version of telegram-channel in the Cargo.lock file from 0.2.1 to 0.2.6. A critical security review has identified that the Cargo.lock file may be compromised by a supply chain attack, as it includes suspicious dependencies and modified versions of core crates like serde and serde_json.
| [[package]] | ||
| name = "telegram-channel" | ||
| version = "0.2.1" | ||
| version = "0.2.6" |
There was a problem hiding this comment.
The Cargo.lock file appears to be compromised. It includes suspicious dependencies (serde_core at line 155, zmij at line 398) that are not part of the official serde ecosystem. Core crates like serde (line 145) and serde_json (line 175) have been modified to depend on these, and serde_json is using a suspicious version number (1.0.149). This is characteristic of a supply chain attack. Do not merge this PR.
zmanian
left a comment
There was a problem hiding this comment.
Trivial lock file bump (telegram-channel 0.2.1 -> 0.2.6). CI green.
No description provided.