From 441fac8e6202375ab00c0a0ddf93525d5f7617b3 Mon Sep 17 00:00:00 2001 From: Alec Wenzowski Date: Thu, 27 Aug 2026 19:32:44 +0000 Subject: [PATCH] fix(deps): chacha20 0.10.1 is yanked, so `deny` refuses every branch MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `mise run deny` fails `advisories` on the committed lockfile: error[yanked]: detected yanked crate (try `cargo update -p chacha20`) chacha20 0.10.1 registry+https://github.com/rust-lang/crates.io-index `chacha20` 0.10.0 and 0.10.1 are both yanked; **0.10.2 is published and is not**. It arrives transitively via `rand`, and 0.10.2 satisfies the existing requirement, so this is one relocked package, `Cargo.lock` only, no manifest change and no API surface. After it: `advisories ok, bans ok, licenses ok, sources ok`. WHY THIS BLOCKS EVERYONE. `ci.yml` carries no `paths:` filter and `[tasks.ci]` is `depends = ["hooks", "deny"]`, so `deny` runs in the `ci` job on every non-draft PR, and `ci` is in `CI_REQUIRED_CHECKS`. Reproduced on a detached worktree at untouched `origin/main`: identical failure. HOW `main` WENT RED WITH CI GREEN, because that is the part worth writing down rather than the bump. CI grades a SHA once, on its PR; `main` then advances only by fast-forward to that exact SHA, and there is deliberately no push-to-`main` trigger — `ci.yml` says re-running would be "pure waste" and AGENTS.md forbids it. That is airtight for a gate whose verdict is a property of the COMMIT. It is false for one whose verdict is a property of the WORLD: `cargo deny check advisories` reads live yank data, `chacha20 0.10.1` was not yanked when these SHAs were graded, and nothing re-asks. The only `ci.yml` runs on `main` are four from 2026-08-05, so "main is green" is a statement about the past. Third instance of that class: `lock-check` (mise releases, already split into `lock-complete` plus `lock-currency.yml`), `semver` (CLOUD-1074, `bisync` yanked, fixed by the `gix` floor bump), and this. `.claude/rules/toolchain.md` carries the rule from the first one's post-mortem — "a property of the commit belongs in the gate, a property of the world belongs on a clock" — and `deny`'s advisory half is on the wrong side of it. Splitting it is filed rather than done here: it changes what a required check means, and the DoR wants a deny gate's firing rate replayed before its severity is chosen. SERVES CLOUD-1077 AND NOT CLOUD-1074, corrected after `claim-not-raced` refused the first spelling. CLOUD-1074's §7 Done clause reads "and `mise run deny` stays green over the changed dependency closure", so serving it looked arguable — but `claim-check` answered `not-todo (in In Progress)`, assigned, with PR #714 already attached, and a row that is claimed and carries a PR cannot be a second PR's closing key. That is exactly what `claim-not-raced` then reported on this branch. Different crate, different gate, different work. Refs: CLOUD-1077, CLOUD-1074 --- Cargo.lock | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index d0dbe1683..2fc6271c9 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -255,9 +255,9 @@ checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" [[package]] name = "chacha20" -version = "0.10.1" +version = "0.10.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d524456ba66e72eb8b115ff89e01e497f8e6d11d78b70b1aa13c0fbd97540a81" +checksum = "65c35e4b699c7e15ccbe7ee35c005e4fc0a278d22238a2857e6ce2dadeda1b06" dependencies = [ "cfg-if", "cpufeatures 0.3.0",