Skip to content

cargo-audit advisories unresolved: h2 0.3.27 (RUSTSEC-2026-0258) and rustls-webpki 0.101.7 (RUSTSEC-2026-0098) #1203

Description

@nanaf6203-bit

Context: AUDIT_LOG.md records cargo-audit findings: h2 0.3.27 (RUSTSEC-2026-0258, fix >= 0.4.16) and rustls-webpki 0.101.7 (RUSTSEC-2026-0098) in the dependency graph (via substrate/ink toolchain).

Problem: The workspace's pinned transitive dependencies carry published security advisories; contract code (bridge transports, off-chain indexers) may parse untrusted network data through these crates, and CI does not fail on audit (no audit step wired to the corrected deny config).

Proposed approach: Bump to advisory-safe versions (h2 >= 0.4.16; rustls-webpki per advisory), or pin older transitive versions deliberately with a [patch]/lockfile comment + audit.toml ignore with justification; re-run cargo audit and record results in AUDIT_LOG.

Acceptance criteria: cargo audit reports zero unignored critical/high advisories; change documented.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Medium ComplexityStellar WaveIssues in the Stellar wave programbugSomething isn't workingsecuritysecurity related issues

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions