Repository navigation
fix: update serde_with to patched 3.23 release - #170
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #170 +/- ##
=======================================
Coverage 81.34% 81.34%
=======================================
Files 39 39
Lines 1576 1576
=======================================
Hits 1282 1282
Misses 294 294 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
CramBL
left a comment
There was a problem hiding this comment.
Thanks! This is a great change, but I have 2 requests:
- Change the version bound from
~3.23to3since there's no reason to not allow newer minor/patch releases, users can choose themselves. - Include more context in the commit message (mention the vulnerability, and now, the change to the version bounds). The commit message is much more important than the PR body and currently the PR body is very useful while the commit message is very generic
The ~3.11 requirement prevents downstream projects from selecting releases patched for GHSA-7gcf-g7xr-8hxj. The advisory describes a KeyValueMap panic when serializing empty sequence or map entries, which can terminate the application. Relax the optional serde_with requirement to 3 so downstream users can choose compatible 3.x minor and patch releases. Refresh the workspace lockfile to the patched 3.23.0 release; the advisory was fixed in 3.21.0. Raise the library and benchmark-harness MSRV to Rust 1.88 to match the locked serde_with release, and update the README and CI matrix. Convert two nested conditions to equivalent let chains to satisfy Clippy at the new MSRV without changing parser behavior. Advisory: GHSA-7gcf-g7xr-8hxj
4023aea to
b2e7e4f
Compare
Thanks, fixed both. I am used to working in repos where the PR description gets folded into the squashed commit, so didn't think to update the commit message. |
|
I've messaged @elpiel and we need him to take action before we can merge this. The issue is that the msrv job has the specific rust version in the job name, and it's configured to be a |
elpiel
left a comment
There was a problem hiding this comment.
All good imo.
Not sure why we left ~3.11
Yes probably just an oversight or an attempt to be rigorous with compatibility. We still need the changes to CI to be able to merge this and future PRs. |
|
Done. This requires a Minor update though so keep that in mind @CramBL |
The
serde_with = "~3.11"constraint prevents downstream projects from resolving a version patched for GHSA-7gcf-g7xr-8hxj. Relax it to3so downstream users can choose compatible minor and patch releases, and regenerate the workspace lockfile with patchedserde_with3.23.0.The locked
serde_withrelease requires Rust 1.88. Update the library and benchmark-harness MSRV, README, and CI matrix accordingly. Convert two nested conditions to equivalent let chains required by Clippy at the new MSRV; parser behavior is unchanged.