Context: AUDIT_LOG.md records cargo-audit findings: h2 0.3.27 (RUSTSEC-2026-0258, fix >= 0.4.16) and rustls-webpki 0.101.7 (RUSTSEC-2026-0098) in the dependency graph (via substrate/ink toolchain).
Problem: The workspace's pinned transitive dependencies carry published security advisories; contract code (bridge transports, off-chain indexers) may parse untrusted network data through these crates, and CI does not fail on audit (no audit step wired to the corrected deny config).
Proposed approach: Bump to advisory-safe versions (h2 >= 0.4.16; rustls-webpki per advisory), or pin older transitive versions deliberately with a [patch]/lockfile comment + audit.toml ignore with justification; re-run cargo audit and record results in AUDIT_LOG.
Acceptance criteria: cargo audit reports zero unignored critical/high advisories; change documented.
Context:
AUDIT_LOG.mdrecordscargo-auditfindings:h20.3.27 (RUSTSEC-2026-0258, fix >= 0.4.16) andrustls-webpki0.101.7 (RUSTSEC-2026-0098) in the dependency graph (via substrate/ink toolchain).Problem: The workspace's pinned transitive dependencies carry published security advisories; contract code (bridge transports, off-chain indexers) may parse untrusted network data through these crates, and CI does not fail on audit (no audit step wired to the corrected deny config).
Proposed approach: Bump to advisory-safe versions (h2 >= 0.4.16; rustls-webpki per advisory), or pin older transitive versions deliberately with a
[patch]/lockfile comment +audit.tomlignore with justification; re-runcargo auditand record results in AUDIT_LOG.Acceptance criteria:
cargo auditreports zero unignored critical/high advisories; change documented.