From 5fede123e71f8bb15f7a3886520da3c2c922519d Mon Sep 17 00:00:00 2001 From: Duncan Tourolle Date: Sat, 22 Aug 2026 11:49:16 +0200 Subject: [PATCH] fix(deps): take the patched quick-xml via plist 1.10 cargo-deny went red on master with two quick-xml DoS advisories (RUSTSEC-2026-0194, RUSTSEC-2026-0195). They were absent before, and correctly so: quick-xml reached the graph only through plist on Apple targets, and deny.toml scopes the graph to the targets this project actually ships. The Tauri 2.11 upgrade changed that. plist is now pulled in by tauri-utils, which is a build-dependency of tauri-build, so it compiles on every target including Linux and the advisory became genuinely in scope. That is the gate behaving as designed -- silent while the crate was unreachable, loud the moment a dependency upgrade brought it into a build we ship. Fixed rather than ignored. plist 1.10.0 requires quick-xml ^0.41.0, which carries both patches, and tauri-utils accepts plist ^1, so the upgrade is a lockfile change with nothing else moving: plist 1.8.0 -> 1.10.0 quick-xml 0.38.4 -> 0.41.0 An ignore entry would have been easy to justify here -- build-time only, parsing files we generate, absent from every shipped binary -- and that is exactly why it would have been wrong: the justification would have outlived the reason for it, and the entry would still be sitting in deny.toml long after the upgrade became available. No release. quick-xml is a build dependency, so it is not inside any v0.10.1 artifact; this only restores master to green. Verified: cargo deny (advisories, bans, licences, sources all ok), cargo check, 765 tests, cargo fmt --check, clippy -D warnings. --- src-tauri/Cargo.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/src-tauri/Cargo.lock b/src-tauri/Cargo.lock index b96e3fde..32751700 100644 --- a/src-tauri/Cargo.lock +++ b/src-tauri/Cargo.lock @@ -3285,9 +3285,9 @@ checksum = "7edddbd0b52d732b21ad9a5fab5c704c14cd949e5e9a1ec5929a24fded1b904c" [[package]] name = "plist" -version = "1.8.0" +version = "1.10.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "740ebea15c5d1428f910cd1a5f52cebf8d25006245ed8ade92702f4943d91e07" +checksum = "7da1d65da6dd5d1e44199ac0f58712d241c0f439f80adea8924d832384087f85" dependencies = [ "base64 0.22.1", "indexmap 2.12.1", @@ -3463,9 +3463,9 @@ dependencies = [ [[package]] name = "quick-xml" -version = "0.38.4" +version = "0.41.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b66c2058c55a409d601666cffe35f04333cf1013010882cec174a7467cd4e21c" +checksum = "e660451e55124f798a69a5af3f49ccfbefbd41910eefd25caf2393e1f3473ec1" dependencies = [ "memchr", ]