diff --git a/Cargo.lock b/Cargo.lock index 59e165168..4cbac092d 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1459,18 +1459,19 @@ dependencies = [ [[package]] name = "cargo-platform" -version = "0.1.9" +version = "0.3.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e35af189006b9c0f00a064685c727031e3ed2d8020f7ba284d78cc2671bd36ea" +checksum = "87a0c0e6148f11f01f32650a2ea02d532b2ad4e81d8bd41e6e565b5adc5e6082" dependencies = [ "serde", + "serde_core", ] [[package]] name = "cargo_metadata" -version = "0.19.2" +version = "0.23.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "dd5eb614ed4c27c5d706420e4320fbe3216ab31fa1c33cd8246ac36dae4479ba" +checksum = "ef987d17b0a113becdd19d3d0022d04d7ef41f9efe4f3fb63ac44ba61df3ade9" dependencies = [ "camino", "cargo-platform", @@ -3002,7 +3003,7 @@ dependencies = [ "js-sys", "log", "wasm-bindgen", - "windows-core", + "windows-core 0.57.0", ] [[package]] @@ -3944,6 +3945,16 @@ dependencies = [ "bitflags", ] +[[package]] +name = "objc2-io-kit" +version = "0.3.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "71c1c64d6120e51cd86033f67176b1cb66780c2efe34dec55176f77befd93c0a" +dependencies = [ + "libc", + "objc2-core-foundation", +] + [[package]] name = "object" version = "0.36.7" @@ -4807,9 +4818,9 @@ dependencies = [ [[package]] name = "regex" -version = "1.11.1" +version = "1.12.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b544ef1b4eac5dc2db33ea63606ae9ffcfac26c1416a2806ae0bf5f56b201191" +checksum = "e10754a14b9137dd7b1e3e5b0493cc9171fdd105e0ab477f51b72e7f3ac0e276" dependencies = [ "aho-corasick", "memchr", @@ -4819,9 +4830,9 @@ dependencies = [ [[package]] name = "regex-automata" -version = "0.4.9" +version = "0.4.14" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "809e8dc61f6de73b46c85f4c96486310fe304c434cfa43669d7b40f711150908" +checksum = "6e1dd4122fc1595e8162618945476892eefca7b88c52820e74af6262213cae8f" dependencies = [ "aho-corasick", "memchr", @@ -6285,14 +6296,15 @@ dependencies = [ [[package]] name = "sysinfo" -version = "0.34.2" +version = "0.37.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a4b93974b3d3aeaa036504b8eefd4c039dced109171c1ae973f1dc63b2c7e4b2" +checksum = "16607d5caffd1c07ce073528f9ed972d88db15dd44023fa57142963be3feb11f" dependencies = [ "libc", "memchr", "ntapi", "objc2-core-foundation", + "objc2-io-kit", "windows", ] @@ -6945,9 +6957,9 @@ checksum = "accd4ea62f7bb7a82fe23066fb0957d48ef677f6eeb8215f372f52e48bb32426" [[package]] name = "vergen" -version = "9.0.6" +version = "9.1.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "6b2bf58be11fc9414104c6d3a2e464163db5ef74b12296bda593cac37b6e4777" +checksum = "b849a1f6d8639e8de261e81ee0fc881e3e3620db1af9f2e0da015d4382ceaf75" dependencies = [ "anyhow", "cargo_metadata", @@ -6962,9 +6974,9 @@ dependencies = [ [[package]] name = "vergen-gitcl" -version = "1.0.8" +version = "9.1.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b9dfc1de6eb2e08a4ddf152f1b179529638bedc0ea95e6d667c014506377aefe" +checksum = "77ff3b5300a085d6bcd8fc96a507f706a28ae3814693236c9b409db71a1d15b9" dependencies = [ "anyhow", "derive_builder", @@ -6976,9 +6988,9 @@ dependencies = [ [[package]] name = "vergen-lib" -version = "0.1.6" +version = "9.1.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9b07e6010c0f3e59fcb164e0163834597da68d1f864e2b8ca49f74de01e9c166" +checksum = "b34a29ba7e9c59e62f229ae1932fb1b8fb8a6fdcc99215a641913f5f5a59a569" dependencies = [ "anyhow", "derive_builder", @@ -7225,12 +7237,24 @@ checksum = "712e227841d057c1ee1cd2fb22fa7e5a5461ae8e48fa2ca79ec42cfc1931183f" [[package]] name = "windows" -version = "0.57.0" +version = "0.61.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "12342cb4d8e3b046f3d80effd474a7a02447231330ef77d71daa6fbc40681143" +checksum = "9babd3a767a4c1aef6900409f85f5d53ce2544ccdfaa86dad48c91782c6d6893" dependencies = [ - "windows-core", - "windows-targets 0.52.6", + "windows-collections", + "windows-core 0.61.2", + "windows-future", + "windows-link 0.1.3", + "windows-numerics", +] + +[[package]] +name = "windows-collections" +version = "0.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3beeceb5e5cfd9eb1d76b381630e82c4241ccd0d27f1a39ed41b2760b255c5e8" +dependencies = [ + "windows-core 0.61.2", ] [[package]] @@ -7239,12 +7263,36 @@ version = "0.57.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "d2ed2439a290666cd67ecce2b0ffaad89c2a56b976b736e6ece670297897832d" dependencies = [ - "windows-implement", - "windows-interface", + "windows-implement 0.57.0", + "windows-interface 0.57.0", "windows-result 0.1.2", "windows-targets 0.52.6", ] +[[package]] +name = "windows-core" +version = "0.61.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c0fdd3ddb90610c7638aa2b3a3ab2904fb9e5cdbecc643ddb3647212781c4ae3" +dependencies = [ + "windows-implement 0.60.2", + "windows-interface 0.59.3", + "windows-link 0.1.3", + "windows-result 0.3.4", + "windows-strings", +] + +[[package]] +name = "windows-future" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "fc6a41e98427b19fe4b73c550f060b59fa592d7d686537eebf9385621bfbad8e" +dependencies = [ + "windows-core 0.61.2", + "windows-link 0.1.3", + "windows-threading", +] + [[package]] name = "windows-implement" version = "0.57.0" @@ -7256,6 +7304,17 @@ dependencies = [ "syn 2.0.104", ] +[[package]] +name = "windows-implement" +version = "0.60.2" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "053e2e040ab57b9dc951b72c264860db7eb3b0200ba345b4e4c3b14f67855ddf" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.104", +] + [[package]] name = "windows-interface" version = "0.57.0" @@ -7267,6 +7326,17 @@ dependencies = [ "syn 2.0.104", ] +[[package]] +name = "windows-interface" +version = "0.59.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3f316c4a2570ba26bbec722032c4099d8c8bc095efccdc15688708623367e358" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.104", +] + [[package]] name = "windows-link" version = "0.1.3" @@ -7279,6 +7349,16 @@ version = "0.2.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "45e46c0661abb7180e7b9c281db115305d49ca1709ab8242adf09666d2173c65" +[[package]] +name = "windows-numerics" +version = "0.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9150af68066c4c5c07ddc0ce30421554771e528bde427614c61038bc2c92c2b1" +dependencies = [ + "windows-core 0.61.2", + "windows-link 0.1.3", +] + [[package]] name = "windows-registry" version = "0.5.3" @@ -7410,6 +7490,15 @@ dependencies = [ "windows_x86_64_msvc 0.53.0", ] +[[package]] +name = "windows-threading" +version = "0.1.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b66463ad2e0ea3bbf808b7f1d371311c80e115c0b71d60efc142cafbcfb057a6" +dependencies = [ + "windows-link 0.1.3", +] + [[package]] name = "windows_aarch64_gnullvm" version = "0.42.2" diff --git a/Cargo.toml b/Cargo.toml index 0c3885792..f642dfc08 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -182,7 +182,7 @@ glob = "=0.3.3" hostname = "=0.4.2" nom = "=8.0.0" phf_codegen = "=0.13.1" -vergen-gitcl = { version = "=1.0.8", features = ["build", "cargo", "rustc", "si"] } +vergen-gitcl = { version = "=9.1.0", features = ["build", "cargo", "rustc", "si"] } # ------------------------------------------------------------------------------ # Binaries diff --git a/supply-chain/audits.toml b/supply-chain/audits.toml index 9a047056e..1c4948cf9 100644 --- a/supply-chain/audits.toml +++ b/supply-chain/audits.toml @@ -527,6 +527,18 @@ criteria = "safe-to-deploy" delta = "2.1.5 -> 2.1.8" notes = "Only Rust change is ethereum_kzg_settings/mod.rs: 16 OnceBox statics -> one [OnceLock;16] array (std::sync::OnceLock or once_cell OnceBox), panic!->assert!. No new unsafe/extern C/transmute/pointers; build.rs unchanged; no network/fs/env access. C/blst diff is internal crypto refinement (g1_add/fr_* wrappers, 383->384 inverse-mod asm, batch affine, g1_ifft->g1_ifft_unscaled) with no new Rust FFI s" +[[audits.cargo-platform]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "0.1.9 -> 0.3.2" +notes = "Benign feature additions (raw identifiers in cfg expressions, boolean cfg literals, keyword warnings) and a dependency optimization (serde -> serde_core). No unsafe code, no network/IO, no build scripts. No advisories." + +[[audits.cargo_metadata]] +who = "Daniel Freire (audited by pi with glm-5.2)" +criteria = "safe-to-deploy" +delta = "0.19.2 -> 0.23.1" +notes = "Reviewed 0.19.2 -> 0.23.1 via cargo vet diff. Benign: newtype wrappers (FeatureName/PackageName) with Deref/AsRef/PartialEq, Metadata.build_directory field stabilization, env_remove helper, default-generic Result, inline format strings, re-export of cargo_platform, routine dep bumps (camino/cargo-platform/semver/serde/serde_json/thiserror). No unsafe, no build scripts, no proc-macros, no new network/IO; Command::new hits are pre-existing doc-examples/tests (the crate shells out to `cargo metadata` by design). delta_from 0.19.2 valid via bytecode-alliance foreign audit (imports.lock, delta 0.18.1 -> 0.19.2). MSRV bump 1.78 -> 1.86 (stratus toolchain 1.97). Breaking API type changes (Package.name->PackageName, Dependency.source Option->Option) don't affect stratus (cargo_metadata is transitive via vergen build-dep only). No RustSec advisories." + [[audits.chrono]] who = "Rodrigo Bronzelle " criteria = "safe-to-deploy" @@ -824,6 +836,12 @@ criteria = "safe-to-deploy" delta = "0.2.0 -> 0.2.1" notes = "Reviewed local diff for security-sensitive behavior; no backdoors, suspicious code execution, network/process/filesystem exfiltration, or private data leakage found." +[[audits.objc2-io-kit]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +version = "0.3.1" +notes = "Auto-generated FFI binding crate to Apple's IOKit framework from the well-known objc2 ecosystem. No build scripts, no proc macros. All unsafe code is standard FFI declarations and objc2 trait implementations. No advisories." + [[audits.opentelemetry]] who = "gabriel-aranha-cw " criteria = "safe-to-deploy" @@ -989,6 +1007,18 @@ criteria = "safe-to-deploy" version = "4.2.0" notes = "Inspected 4.2.0: pure hashing crate; default build keeps safety checks. Unsafe usage limited to guarded pointer reads in util::read with explicit length assertions; no I/O or syscalls." +[[audits.regex]] +who = "Daniel Freire (audited by pi with glm-5.2)" +criteria = "safe-to-deploy" +delta = "1.11.1 -> 1.12.3" +notes = "Reviewed 1.11.1 -> 1.12.3 via cargo vet diff. Bug-fix/doc releases across 1.11.2-1.12.3: one additive method Captures::get_match(), lazy-DFA/sparse-DFA memory fixes (1.12.0), 1.12.0 yanked + lifetime fix in 1.12.1, archive/test-data cleanup. regex is entirely unsafe-free (no unsafe/extern/transmute/Command/net/fs in the src diff). MSRV unchanged 1.65. No RustSec advisories. stratus uses regex only transitively (sentry-backtrace, bindgen/vergen build-deps)." + +[[audits.regex-automata]] +who = "Daniel Freire (audited by pi with glm-5.2)" +criteria = "safe-to-deploy" +delta = "0.4.9 -> 0.4.14" +notes = "Reviewed 0.4.9 -> 0.4.14 via cargo vet diff. Unsafe footprint identical between versions (37 unsafe blocks, 12 unsafe fn, 7 unsafe impl, 3 transmute; 0 added unsafe/extern/transmute/Command/net/fs). Hardening: corrupted dense DFA deserialize now errors instead of panicking (#1295), shrink_to_fit memory trims, additive DFA::set_prefilter(), perf-literal-multisubstring no longer implies std. No new deps/IO/network/build scripts. MSRV unchanged 1.65. No RustSec advisories. stratus uses regex-automata only transitively (via regex)." + [[audits.revm]] who = "gabriel-aranha-cw " criteria = "safe-to-deploy" @@ -1271,6 +1301,12 @@ criteria = "safe-to-deploy" delta = "1.4.1 -> 1.6.1" notes = "Diff is minimal and confined to Cargo.toml (version bump only, build=false, no new deps) plus 3 source files: stmt/mod.rs adds a `delete` keyword parser branch (routes to Stmt::Expr, with cfg(test) tests), type/mod.rs removes a deprecated is_one_word method, variable/mod.rs refactors fmt_eip712 to recurse into Type::Array for EIP-712 formatting. No unsafe, FFI, transmute, build.rs, network, fs/env" +[[audits.sysinfo]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "0.34.2 -> 0.37.2" +notes = "Read-only system-information crate. Delta is bug fixes, new read-only APIs, and adoption of objc2-io-kit bindings. Unsafe footprint largely unchanged (mostly #[unsafe(no_mangle)] edition syntax changes). No advisories." + [[audits.tag_ptr]] who = "Daniel Freire (audited by pi with glm-5.2)" criteria = "safe-to-deploy" @@ -1342,6 +1378,72 @@ criteria = "safe-to-deploy" delta = "1.18.1 -> 1.23.3" notes = "Reviewed uuid 1.18.1 -> 1.23.3 via cargo vet diff and upstream sources. Changes are maintenance/bug-fix release spanning 1.19.0-1.23.3: edition 2021, dependency updates (getrandom 0.3->0.4, rand 0.9->0.10, serde renamed to serde_core alias), v7 monotonicity/counter correctness fixes, parser panic fix, and removal of uuid-macro-internal proc-macro in favor of a declarative const macro. No new unsafe code; the existing unsafe is unchanged and limited to ASCII hex formatting transmutes. No network/filesystem/process I/O, build scripts, or crypto changes. No RustSec advisories. MSRV raised to 1.85.0; project uses Rust 1.88. Breaking changes (serde adapter strictness, deprecated Context/ContextV1, Timestamp::from_gregorian_time) are not used in stratus. Project only uses Uuid::now_v7() and Uuid::nil() via uuid v7 feature." +[[audits.vergen]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "9.0.6 -> 9.1.0" +notes = "Workspace-wide version alignment and Rust 2024 edition migration. No logic changes to core functions. Unsafe usage is only env::set_var() wrapped in unsafe {} to comply with Rust 2024 semantics, behind a non-default feature. No advisories." + +[[audits.vergen-gitcl]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "1.0.8 -> 9.1.0" +notes = "Workspace-wide version alignment, not a breaking API change. Zero logic changes to run_cmd, git entry computation, or dirty/local offset logic. Only import reordering, lint updates for Rust 2024, and build.rs simplification. No advisories." + +[[audits.vergen-lib]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "0.1.6 -> 9.1.0" +notes = "Workspace-wide edition-2024 synchronization. Only meaningful delta is unsafe { env::set_var(...) } required by Rust 2024 semantics, behind a non-default feature. No new dependencies, no network/IO. No advisories." + +[[audits.windows]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "0.57.0 -> 0.61.3" +notes = "Massive diff is almost entirely auto-generated Windows API bindings from ECMA-335 metadata, which is the normal mode of operation. Manual code additions are small, safe convenience wrappers. Replaced windows-targets binary blobs with windows-link (native raw-dylib), a net security improvement. No advisories." + +[[audits.windows-collections]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +version = "0.2.0" +notes = "Thin in-memory adapter bridging Rust collections to Windows Runtime interfaces. No manual unsafe blocks. Unsafe surface limited to standard auto-generated COM bindings. No build scripts, no network/IO. No advisories." + +[[audits.windows-core]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "0.57.0 -> 0.61.2" +notes = "Restructuring to adopt windows-link and eliminate windows-targets. Unsafe footprint dropped by ~50% (435 -> 223 occurrences). Removed unsafe wrappers (heap.rs, delay_load.rs, waiter.rs). event.rs refactored from manual unsafe memory management to safe Arc + RwLock. No advisories." + +[[audits.windows-future]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +version = "0.2.1" +notes = "Official Microsoft WinRT async interface wrappers. No build scripts, no proc macros. Unsafe code is limited to auto-generated COM vtables and well-documented Win32 sync API calls. No advisories." + +[[audits.windows-implement]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "0.57.0 -> 0.60.2" +notes = "Proc-macro crate refactoring: split monolithic lib.rs into gen.rs and tests.rs. Added opt-in Agile = true/false attribute for COM implementations. No new dependencies. No unsafe in the macro itself. No advisories." + +[[audits.windows-interface]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +delta = "0.57.0 -> 0.59.3" +notes = "Proc-macro refactoring of COM vtable generation. Simplified dispatch logic by removing Impl associated type. No new unsafe in macro source, no new dependencies, no build scripts. No advisories." + +[[audits.windows-numerics]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +version = "0.2.0" +notes = "Small math library with 3 localized FFI calls to documented Windows system DLLs (d2d1.dll). No build scripts, no proc macros, no network/IO, no crypto. No advisories." + +[[audits.windows-threading]] +who = "Droid (cargo-vet automation)" +criteria = "safe-to-deploy" +version = "0.1.0" +notes = "Thin no_std wrapper over standard Windows thread pool APIs (kernel32.dll). All unsafe is tightly scoped to FFI calls. Safe public API enforces Send/Sync/'static. No build scripts, no proc macros. No advisories." + [[audits.winnow]] who = "Daniel Freire (audited by pi with glm-5.2)" criteria = "safe-to-deploy"