Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump trycmd to 0.15.1 #539

Closed
wants to merge 1 commit into from

Conversation

joshka
Copy link
Contributor

@joshka joshka commented Apr 8, 2024

Fixes the race condition in remove_dir all as it is no longer a
dependency. See GHSA-mc8h-8q98-g5hr

Before:

❯ cargo tree -i remove_dir_all
remove_dir_all v0.5.3
└── tempfile v3.3.0
    ├── prost-build v0.12.0
    │   └── tonic-build v0.10.0
    │       └── xtask v0.1.0 (/Users/joshka/local/tokio-console/xtask)
    │       [dev-dependencies]
    │       └── console-api v0.6.0 (/Users/joshka/local/tokio-console/console-api)
    │           ├── console-subscriber v0.2.0 (/Users/joshka/local/tokio-console/console-subscriber)
    │           └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)
    │   [dev-dependencies]
    │   └── console-api v0.6.0 (/Users/joshka/local/tokio-console/console-api) (*)
    └── snapbox v0.5.9
        └── trycmd v0.15.1
            [dev-dependencies]
            └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)

After:

❯ cargo tree -i remove_dir_all
error: package ID specification `remove_dir_all` did not match any packages

Fixes the race condition in remove_dir all as it is no longer a
dependency. See GHSA-mc8h-8q98-g5hr

Before:
```
❯ cargo tree -i remove_dir_all
remove_dir_all v0.5.3
└── tempfile v3.3.0
    ├── prost-build v0.12.0
    │   └── tonic-build v0.10.0
    │       └── xtask v0.1.0 (/Users/joshka/local/tokio-console/xtask)
    │       [dev-dependencies]
    │       └── console-api v0.6.0 (/Users/joshka/local/tokio-console/console-api)
    │           ├── console-subscriber v0.2.0 (/Users/joshka/local/tokio-console/console-subscriber)
    │           └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)
    │   [dev-dependencies]
    │   └── console-api v0.6.0 (/Users/joshka/local/tokio-console/console-api) (*)
    └── snapbox v0.5.9
        └── trycmd v0.15.1
            [dev-dependencies]
            └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)
```
After:
```
❯ cargo tree -i remove_dir_all
error: package ID specification `remove_dir_all` did not match any packages
```
@joshka joshka requested a review from a team as a code owner April 8, 2024 16:37
@joshka
Copy link
Contributor Author

joshka commented Apr 8, 2024

Additionally this fixes GHSA-g98v-hv3f-hcfr (atty unaligned read)
Before:

❯ cargo tree -i atty
atty v0.2.14
└── concolor v0.0.8
    └── snapbox v0.3.3
        └── trycmd v0.13.6
            [dev-dependencies]
            └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)

After:

❯ cargo tree -i atty
error: package ID specification `atty` did not match any packages

@joshka
Copy link
Contributor Author

joshka commented Apr 8, 2024

And probably fixes GHSA-c827-hfw6-qwvm too (based on the version range in the advisory):

Affected versions
>= 0.35.11, < 0.35.15
>= 0.36.0, < 0.36.16
>= 0.37.0, < 0.37.25
>= 0.38.0, < 0.38.19
Patched versions
0.35.15
0.36.16
0.37.25
0.38.19

After: (two versions of rustix in deps)

❯ cargo tree -i [email protected]
rustix v0.37.27
└── terminal_size v0.2.6
    └── clap_builder v4.1.14
        └── clap v4.1.14
            ├── clap_complete v4.1.6
            │   └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)
            ├── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)
            └── xtask v0.1.0 (/Users/joshka/local/tokio-console/xtask)

❯ cargo tree -i [email protected]
rustix v0.38.32
└── tempfile v3.10.1
    ├── prost-build v0.12.4
    │   └── tonic-build v0.10.2
    │       └── xtask v0.1.0 (/Users/joshka/local/tokio-console/xtask)
    │       [dev-dependencies]
    │       └── console-api v0.6.0 (/Users/joshka/local/tokio-console/console-api)
    │           ├── console-subscriber v0.2.0 (/Users/joshka/local/tokio-console/console-subscriber)
    │           └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)
    │   [dev-dependencies]
    │   └── console-api v0.6.0 (/Users/joshka/local/tokio-console/console-api) (*)
    └── snapbox v0.5.9
        └── trycmd v0.15.1
            [dev-dependencies]
            └── tokio-console v0.1.10 (/Users/joshka/local/tokio-console/tokio-console)

@hi-rustin
Copy link
Collaborator

Thanks for your contribution! 🤟 🖤

This PR also involves very many changes that have nothing to do with trycmd. It's best to upgrade it separately rather than updating the entire lockfile directly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants