Updated security-sensitive Rust dependencies (#706)
Build and Release / Read metadata (push) Waiting to run
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-apple-darwin, osx-arm64, macos-latest, aarch64-apple-darwin, dmg updater) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-pc-windows-msvc.exe, win-arm64, windows-latest, aarch64-pc-windows-msvc, nsis updater) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-aarch64-unknown-linux-gnu, linux-arm64, ubuntu-22.04-arm, aarch64-unknown-linux-gnu, appimage deb updater) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-apple-darwin, osx-x64, macos-latest, x86_64-apple-darwin, dmg updater) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-pc-windows-msvc.exe, win-x64, windows-latest, x86_64-pc-windows-msvc, nsis updater) (push) Blocked by required conditions
Build and Release / Build app (${{ matrix.dotnet_runtime }}) (-x86_64-unknown-linux-gnu, linux-x64, ubuntu-22.04, x86_64-unknown-linux-gnu, appimage deb updater) (push) Blocked by required conditions
Build and Release / Prepare & create release (push) Blocked by required conditions
Build and Release / Publish release (push) Blocked by required conditions

This commit is contained in:
Thorsten Sommer authored and GitHub committed 2026-03-22 14:11:30 +01:00
1 parent cf6226546e
commit 309d36897e
5 files changed
+439 -240

No files matched your search

+14 -12
View File
@@ -15,18 +15,17 @@ serde = { version = "1.0.228", features = ["derive"] }
serde_json = "1.0.149"
keyring = { version = "3.6.2", features = ["apple-native", "windows-native", "sync-secret-service"] }
arboard = "3.6.1"
tokio = { version = "1.49.0", features = ["rt", "rt-multi-thread", "macros", "process"] }
tokio = { version = "1.50.0", features = ["rt", "rt-multi-thread", "macros", "process"] }
tokio-stream = "0.1.18"
futures = "0.3.31"
futures = "0.3.32"
async-stream = "0.3.6"
flexi_logger = "0.31.8"
log = { version = "0.4.29", features = ["kv"] }
once_cell = "1.21.3"
once_cell = "1.21.4"
rocket = { version = "0.5.1", features = ["json", "tls"] }
rand = "0.9.1"
rand_chacha = "0.9"
rand = "0.10.0"
rand_chacha = "0.10.0"
base64 = "0.22.1"
cipher = { version = "0.4.4", features = ["std"] }
aes = "0.8.4"
cbc = "0.1.2"
pbkdf2 = "0.12.2"
@@ -34,25 +33,28 @@ hmac = "0.12.1"
sha2 = "0.10.8"
rcgen = { version = "0.14.7", features = ["pem"] }
file-format = "0.28.0"
calamine = "0.33.0"
calamine = "0.34.0"
pdfium-render = "0.8.37"
sys-locale = "0.3.2"
cfg-if = "1.0.4"
pptx-to-md = "0.4.0"
tempfile = "3.8"
strum_macros = "0.27"
sysinfo = "0.38.0"
tempfile = "3.27.0"
strum_macros = "0.28.0"
sysinfo = "0.38.4"
# Fixes security vulnerability downstream, where the upstream is not fixed yet:
time = "0.3.47" # -> Rocket
bytes = "1.11.1" # -> almost every dependency
aws-lc-rs = "1.16.2" # -> reqwest
tar = "0.4.45" # -> Tauri v1
rustls-webpki = "0.103.10" # -> tokio, reqwest
[target.'cfg(target_os = "linux")'.dependencies]
# See issue https://github.com/tauri-apps/tauri/issues/4470
reqwest = { version = "0.13.1", features = ["native-tls-vendored"] }
reqwest = { version = "0.13.2", features = ["native-tls-vendored"] }
# Fixes security vulnerability downstream, where the upstream is not fixed yet:
openssl = "0.10.75"
openssl = "0.10.76" # -> reqwest, Tauri v1
[target.'cfg(target_os = "windows")'.dependencies]
windows-registry = "0.6.1"