Skip to content

Conversation

@lwshang
Copy link
Contributor

@lwshang lwshang commented Jan 5, 2026

Description

The security issue is in rkyv v0.7 and fixed in v0.8.13.
rkyv is an indirect dependency introduced by rust_decimal. rust_decimal cannot bump its rkyv dependency to v0.8 because it will be a breaking change for them. (issue)
I have asked rkyv maintainer to backport the fix to v0.7. (request)

Before the patch is released, let's temporarily ignore this RUSTSET rule to unblock our work.

@lwshang lwshang marked this pull request as ready for review January 5, 2026 15:06
@lwshang lwshang requested a review from a team as a code owner January 5, 2026 15:06
@lwshang lwshang enabled auto-merge (squash) January 5, 2026 15:06
Copy link
Contributor

@adamspofford-dfinity adamspofford-dfinity left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like we don't enable the optional feature that would include the rkyv dependency anyway.

@lwshang lwshang merged commit 898ff94 into master Jan 5, 2026
36 checks passed
@lwshang lwshang deleted the lwshang/fix_audit branch January 5, 2026 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants