Skip to content

chore(deps, rust): update rust-lang.rust-analyzer, usernamehw.errorlens in devcontainer-metadata.json - #122

Open
embedded-releaser-app[bot] wants to merge 1 commit into
mainfrom
feature/embedded-devcontainer-rust/update-vscode-extensions-devcontainer-metadata.json
Open

embedded-releaser-app[bot] wants to merge 1 commit into
mainfrom
feature/embedded-devcontainer-rust/update-vscode-extensions-devcontainer-metadata.json

Conversation

@embedded-releaser-app

@embedded-releaser-app embedded-releaser-app Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Note

Before merging this PR, please conduct a manual test checking basic functionality of the updated plug-ins. There are limited automated tests for the VS Code Extension updates.

Updates usernamehw.errorlens from 3.28.0 to 3.29.0

Release notes

Updates rust-lang.rust-analyzer from 0.3.3033 to 0.3.3065

Release notes

Commit: 03fcb77
Release: 2026-09-28 (v0.3.3065)

New Features

  • #23390 support hover on #[cfg] predicates:

    Screenshot showing a feature=in-rust-tree predicate evaluating to false

Fixes

  • #23407 (first contribution) prioritize required items in trait autocomplete.
  • #23410 (first contribution) keep semantic token cache on refresh.
  • #23416 (first contribution) fix safe to unsafe function coercion.
  • #23185 fix const eval casting of single-variant enums.
  • #23421 report undefined behavior when reading the discriminant of an uninhabited enum.
  • #23409 fix panic in async closures with HRTB.
  • #23365 show trait impl when hovering on methods.
  • #23382 complete #[cfg(false)].
  • #23413 de-duplicate +#[derive]+ and +#[test]+ in completions.
  • #23399 don't duplicate parentheses in attribute completions.
  • #23395, #23414 complete strings in #[cfg] values.
  • #23406, #23405 check for matching types in type alias and const completions.
  • #23408 don't prioritize unknown types in completions.

Internal Improvements

  • #23351 (first contribution) simplify Windows path encoding.
  • #23398 add GenericSubstitution::all_types.
  • #23386 activate extension even when the server fails to start.
  • #23391 ignore nightly date string in xtask codegen.
  • #23429 use GitHub self-repository syntax for release action.

See also the changelog post.

Commit: aaddfb7
Release: 2026-09-21 (v0.3.3057)

New Features

  • #23384 support completions inside cfg!():

    Screenshot showing if cfg!(any(target_)) completions

Fixes

  • #23375 (first contribution) watch include roots recursively only once, on directory.
  • #23370 (first contribution) fix broken server binary check.
  • #23359 (first contribution) cache macro-expanded roots when climbing ancestors.
  • #23367 work around a panic when the trait solver re-enters itself.
  • #23368 return an early error on unsupported string binary operations.
  • #23360 include working directory when discovery command fails.

Internal Improvements

  • #23308 refactor SyntaxContext to not reimplement salsa macros.

See also the changelog post.

Commit: 682a84e
Release: 2026-09-14 (v0.3.3049)

Fixes

  • #23300 (first contribution) fix doc comment offset calculation.
  • #23307 drop support for const blocks in patterns.
  • #23333, #23340 fix incorrect_case false positives on raw identifiers.
  • #23330 fix panic on {"$": ""}.
  • #23295 fix panic on doc comments attached to literal expressions.
  • #23315 fix Type owner mismatches between anonymous consts.
  • #23352 fix an Type::impls_trait panic with built-in derives of generic types.
  • #23323 fix stack overflow with recursive eager macros.
  • #23317 don't fill the body of Drop::drop and #[rustc_must_implement_one_of] items.
  • #23318 skip unstable methods in "Implement default members".

Internal Improvements

  • #23311 clean up some #[allow]s.
  • #23325 remove the interner and db arguments from empty and default_types.

See also the changelog post.

Commit: 9074e9b
Release: 2026-09-07 (v0.3.3041)

New Features

  • #23266 render const values in completion label details:

  • #23262 add missing-body diagnostic.

Performance Improvements

  • #23190 don't lower the signature again in inference, fetch it from other queries instead.

Fixes

  • #23297 (first contribution) follow symlinks when scanning the sysroot for proc macro dylibs.
  • #23279 fix printing of float bit patterns on hover.
  • #23249 accept Self as non-leading path segment in attribute paths.
  • #23246 allow inner attributes on blocks in tuple expressions.
  • #22662 avoid type unification errors in term search.
  • #23163 fix parsing of self:: in function param list.
  • #23270 fix handling of #[unsafe()] attributes without inner meta.

Internal Improvements

  • #23248 (first contribution) use cargo install --locked.
  • #23265 (first contribution) reduce the scope of the marketplace tokens.
  • #23218 store doc comments as their own node and not as COMMENT trivia.
  • #23271 merge Expr::Unsafe into Expr::Block.
  • #23292 make NamedTempFile writable on creation.

See also the changelog post.

@embedded-releaser-app embedded-releaser-app Bot added dependencies Pull requests that update a dependency file vscode-extensions labels Sep 13, 2026
@github-actions

github-actions Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

❌MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 24 0 0 0.22s
✅ ACTION zizmor 24 0 0 0 5.34s
✅ DOCKERFILE hadolint 3 0 0 1.21s
✅ JSON npm-package-json-lint yes no no 0.3s
✅ JSON prettier 22 3 0 0 1.02s
✅ JSON v8r 22 0 0 6.7s
✅ MARKDOWN markdownlint 12 0 0 0 0.62s
✅ MARKDOWN markdown-table-formatter 12 1 0 0 0.15s
✅ REPOSITORY betterleaks yes no no 0.82s
✅ REPOSITORY checkov yes no no 18.36s
✅ REPOSITORY git_diff yes no no 0.01s
❌ REPOSITORY grype yes 2 1 65.94s
❌ REPOSITORY osv-scanner yes 7 no 0.87s
✅ REPOSITORY secretlint yes no no 1.24s
✅ REPOSITORY syft yes no no 1.77s
❌ REPOSITORY trivy yes 2 1 8.94s
✅ REPOSITORY trivy-sbom yes no no 0.21s
✅ REPOSITORY trufflehog yes no no 2.09s
⚠️ SPELL lychee 86 1 0 32.65s
✅ YAML prettier 32 0 0 0 0.57s
✅ YAML v8r 32 0 0 6.04s
✅ YAML yamllint 32 0 0 0.89s

Detailed Issues

❌ REPOSITORY / grype - 2 errors
error: A high vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

error: A high vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

warning: A medium vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

warning: 1 warnings emitted
error: 2 errors emitted
❌ REPOSITORY / osv-scanner - 7 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned package-lock.json file and found 73 packages
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/cortex-mf/Cargo.lock file and found 30 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned test/rust/workspace/cortex-m/Cargo.lock file and found 30 packages
End status: 61 dirs visited, 220 inodes visited, 7 Extract calls, 16.126112ms elapsed, 16.126272ms wall time
Loaded filter from: test/rust/workspace/cortex-m/osv-scanner.toml
Loaded filter from: test/rust/workspace/cortex-mf/osv-scanner.toml
RUSTSEC-2026-0110 has been filtered out because: bare-metal is deprecated/unmaintained upstream with no fixed version; pulled in transitively by cortex-m in this test fixture crate
RUSTSEC-2026-0110 has been filtered out because: bare-metal is deprecated/unmaintained upstream with no fixed version; pulled in transitively by cortex-m in this test fixture crate
Filtered 2 vulnerabilities from output

Total 3 packages affected by 7 known vulnerabilities (0 Critical, 5 High, 2 Medium, 0 Low, 0 Unknown) from 2 ecosystems.
6 vulnerabilities can be fixed.

+-------------------------------------+------+-----------+-----------------------+---------+---------------+------------------------------------+
| OSV URL                             | CVSS | ECOSYSTEM | PACKAGE               | VERSION | FIXED VERSION | SOURCE                             |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+------------------------------------+
| https://osv.dev/PYSEC-2026-4175     | 7.6  | PyPI      | urllib3               | 2.7.0   | 2.8.0         | .devcontainer/cpp/requirements.txt |
| https://osv.dev/GHSA-8988-9cw3-xx77 |      |           |                       |         |               |                                    |
| https://osv.dev/PYSEC-2026-4176     | 6.9  | PyPI      | urllib3               | 2.7.0   | 2.8.0         | .devcontainer/cpp/requirements.txt |
| https://osv.dev/GHSA-gh4c-6fx4-qh6g |      |           |                       |         |               |                                    |
| https://osv.dev/PYSEC-2026-4177     | 8.9  | PyPI      | urllib3               | 2.7.0   | 2.8.0         | .devcontainer/cpp/requirements.txt |
| https://osv.dev/GHSA-vxq7-64xx-v4gw |      |           |                       |         |               |                                    |
| https://osv.dev/GHSA-6j4f-fj2g-mc7p | 7.5  | npm       | brace-expansion (dev) | 5.0.9   | 5.0.10        | package-lock.json                  |
| https://osv.dev/GHSA-q2hr-2g5m-vwhr | 5.3  | npm       | brace-expansion (dev) | 5.0.9   | 5.0.12        | package-lock.json                  |
| https://osv.dev/GHSA-qhr7-859c-m2p7 | 7.5  | npm       | brace-expansion (dev) | 5.0.9   | 5.0.11        | package-lock.json                  |
| https://osv.dev/GHSA-vfj7-8cjw-p6xm | 8.7  | npm       | braces (dev)          | 3.0.3   | --            | package-lock.json                  |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+------------------------------------+
❌ REPOSITORY / trivy - 2 errors
error: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97687
Severity: HIGH
Fixed Version: 2.8.0
Link: [CVE-2026-97687](https://avd.aquasec.com/nvd/cve-2026-97687)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Traffic interception via HTTPS proxy TLS configuration override
    = urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.

error: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97689
Severity: HIGH
Fixed Version: 2.8.0
Link: [CVE-2026-97689](https://avd.aquasec.com/nvd/cve-2026-97689)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Denial of Service via unbounded memory allocation in chunk parser
    = urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.

warning: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97688
Severity: MEDIUM
Fixed Version: 2.8.0
Link: [CVE-2026-97688](https://avd.aquasec.com/nvd/cve-2026-97688)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Denial of Service via infinite loop during chunked Deflate decoding
    = urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.

warning: 1 warnings emitted
error: 2 errors emitted
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........133
🔗 Unique.........112
✅ Successful.....127
⏳ Timeouts.........0
🔀 Redirected......13
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 30:7) | Rejected status code: 403 Forbidden

Hint: Followed 13 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@embedded-releaser-app
embedded-releaser-app Bot force-pushed the feature/embedded-devcontainer-rust/update-vscode-extensions-devcontainer-metadata.json branch from 0ca02f8 to 644bbfc Compare September 20, 2026 07:52
@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing docker.io/gabrielfrasantos/embedded-devcontainer-base:edge ➔ docker.io/gabrielfrasantos/embedded-devcontainer-base:pr-122

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 0 B 1.03 GB +1.03 GB (+∞) 🔼
linux/arm64 0 B 1.03 GB +1.03 GB (+∞) 🔼

@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing docker.io/gabrielfrasantos/embedded-devcontainer-rust:edge ➔ docker.io/gabrielfrasantos/embedded-devcontainer-rust:pr-122

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 0 B 1.46 GB +1.46 GB (+∞) 🔼
linux/arm64 0 B 1.39 GB +1.39 GB (+∞) 🔼

@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing docker.io/gabrielfrasantos/embedded-devcontainer-cpp:edge ➔ docker.io/gabrielfrasantos/embedded-devcontainer-cpp:pr-122

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 732.36 MB 1.54 GB +803.49 MB (+109.71%) 🔼
linux/arm64 0 B 1.51 GB +1.51 GB (+∞) 🔼

@embedded-releaser-app
embedded-releaser-app Bot force-pushed the feature/embedded-devcontainer-rust/update-vscode-extensions-devcontainer-metadata.json branch from 644bbfc to 3d576ff Compare September 27, 2026 08:26
@embedded-releaser-app embedded-releaser-app Bot changed the title chore(deps, rust): update rust-lang.rust-analyzer in devcontainer-metadata.json chore(deps, rust): update rust-lang.rust-analyzer, usernamehw.errorlens in devcontainer-metadata.json Sep 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Test Results

 12 files   12 suites   16m 48s ⏱️
 36 tests  36 ✅ 0 💤 0 ❌
152 runs  152 ✅ 0 💤 0 ❌

Results for commit 3d576ff.

@embedded-releaser-app
embedded-releaser-app Bot force-pushed the feature/embedded-devcontainer-rust/update-vscode-extensions-devcontainer-metadata.json branch from 3d576ff to fcf159a Compare October 4, 2026 08:38

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file vscode-extensions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants