deps: clear the Dependabot alerts that need no major bump - #539
Merged
Merged
Conversation
- rand 0.8.5 -> 0.8.6 (GHSA-cq8v-f236-94qc), root and examples lockfiles. - examples: openssl 0.10.77 -> 0.10.81 and serde_with 3.18 -> 3.22. - gnark-ffi: golang.org/x/crypto 0.35.0 -> 0.52.0 (indirect; only blake2b is imported), which needs Go 1.25, so go 1.25.0 / toolchain go1.25.4. - Cargo.toml: drop a private repository's name from the Plonky3 pin comment.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Clears the Dependabot alerts that need no major-version bump, and removes a private repository's name from a public comment.
rand0.8.5 → 0.8.6 (GHSA-cq8v-f236-94qc) in both lockfiles; inexamples/,openssl0.10.77 → 0.10.81 (GHSA-phqj-4mhp-q6mq, GHSA-xv59-967r-8726 and others) andserde_with3.18 → 3.22 (GHSA-7gcf-g7xr-8hxj). The guest programs build from their own lockfiles, so no guest ELF or verifying key changes.gnark-ffi):golang.org/x/crypto0.35.0 → 0.52.0, which clears thessh/agentadvisories. It is an indirect dependency; onlyblake2bis imported. v0.52 requires Go 1.25, sogo.modmoves togo 1.25.0/toolchain go1.25.4; with the defaultGOTOOLCHAIN=autoan older local Go downloads it.Cargo.toml: the Plonky3 pin comment no longer names a private repository.Not in this PR: the remaining Rust alerts need major bumps, mostly through
ethers2 →reqwest0.11 (hickory-proto,jsonwebtoken,rustls-webpki0.101,ring0.16), pluslru,git2andtracing-subscriber0.2;rsahas no fix. The Plonky3 challenger advisory is handled separately because it changes the wrap verifying key.Test plan
ark), the twelve-packagecargo test -rloop (includingzkm-recursion-gnark-ffibuilt with Go 1.25.4),zkm-picus,zkm-core-machinecost and Weierstrass tests, verifier malformed-input tests under both feature sets — all passed.