Skip to content

Fix dependency vulnerabilities - #7

Draft
tanRdev wants to merge 1 commit into
mainfrom
agent/fix-dependency-vulnerabilities
Draft

Fix dependency vulnerabilities#7
tanRdev wants to merge 1 commit into
mainfrom
agent/fix-dependency-vulnerabilities

Conversation

@tanRdev

@tanRdev tanRdev commented Aug 1, 2026

Copy link
Copy Markdown
Owner

Summary

  • update npm and Rust lockfiles to patched dependency releases
  • move the Windows-only quick-xml chain from 0.37.5 to patched 0.41.0
  • remove the obsolete RustSec exception and require a clean vulnerability audit
  • refresh generated Tauri capability schemas after the Rust updates

Verification

  • npm audit — 0 vulnerabilities
  • cargo audit — 0 vulnerabilities (maintenance/unsoundness warnings remain informational)
  • npm run verify:code — formatting, lint, typecheck, frontend tests/build, Rust fmt/clippy/tests/build, audits, and workflow validation pass

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant