chore(supply-chain): trust dtolnay, whom the imported peers trust, and pre-exempt the rest (LAB-6649) - #93
Conversation
…d pre-exempt the rest (LAB-6649) Every dependency update adds versions that no imported audit or version-pinned exemption covers yet, so `cargo vet` fails on each one. The imported isrg, mozilla and bytecode-alliance feeds trust David Tolnay as a publisher, and `cargo vet` suggests trusting him for the failing serde, serde_core, serde_derive, syn, thiserror and thiserror-impl releases. The existing [[trusted]] entries follow the same rule for other publishers. `cargo vet trust --all dtolnay` records safe-to-deploy trust, ending one year out, for every crate in the graph that he alone publishes. That is those six plus anyhow, itoa, prettyplease, serde_bytes, serde_json and unicode-ident, which until now passed only on version-pinned exemptions. Their new releases now pass without a per-version entry. The nine exemptions that trust makes redundant are removed. The other crates in the pending update have no peer-trusted publisher and no imported audit for the new version, so they get version-pinned exemptions: xxhash-rust 0.8.18, zeroize 1.9.0, zeroize_derive 1.5.0, cbindgen 0.29.4 and getrandom 0.3.4. The existing r-efi 5.3.0 exemption is raised from safe-to-run to safe-to-deploy. cbindgen 0.29.4 moves tempfile, a build dependency, onto getrandom 0.3.4, which pulls r-efi 5.3.0 up with it. None of those versions is in this lock yet, so `cargo vet` warns that `cargo vet prune` would remove them. Do not prune until the update lands. `imports.lock` is the store as `cargo vet trust` rewrote it: publisher records for the newly trusted versions and the peers' current audits.
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 36 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
…isher is trusted (LAB-6649) With dtolnay trusted, `cargo vet` passes each new serde_json release without a per-version entry. serde_json is a dev-dependency, and the inherited rust-dev-deps rule automerges dev-dependency updates once checks pass. Until now the vet check went red on every new version, which kept those updates from automerging. Without this rule, a serde_json release, and the serde_core it resolves (a runtime dependency), would reach main with no human review. The rule sets automerge to false for serde_json. Renovate automerges a group only when every update in it automerges, so a rust-dev-deps group that carries a serde_json update waits for a human as well. serde_json is the only direct dev-dependency among the trusted crates. The others arrive through the non-major group or lock-file maintenance, and neither automerges. The new [[trusted]] entries now end 2027-05-30, the same date as the existing entries, so all trust entries renew together. A correction to the previous commit message: getrandom 0.3.4 is already in this lock, reached through a dev-dependency. Its new safe-to-deploy exemption is kept by `cargo vet prune`, and with the imported delta audits it now also vets getrandom 0.4.2. Only cbindgen 0.29.4, xxhash-rust 0.8.18, zeroize 1.9.0, zeroize_derive 1.5.0 and the r-efi raise wait on the pending update. The dtolnay trust is publisher-wide: the peers trust him as a publisher, and some of their per-crate entries for him have lapsed.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
cargo vetfails on every dependency update, because each update brings in versions that no imported audit or version-pinned exemption covers yet. This change lets releases by a publisher the imported peers already trust pass with no per-version entry. It also pre-exempts the remaining crates in the pending minor/patch update.What changes
Trust David Tolnay (dtolnay) for his crates. For the failing serde, serde_core, serde_derive, syn, thiserror and thiserror-impl releases,
cargo vetreports that the imported isrg, mozilla and bytecode-alliance feeds trust him, and suggestscargo vet trust --all dtolnay. That is trust in the publisher, not per crate. The peers' own per-crate entries for him have lapsed for some of these crates (thiserror, thiserror-impl, itoa, serde_bytes), while others, such as bytecode-alliance's for syn, run to 2027. The existing[[trusted]]entries follow the same rule for other publishers.The command records safe-to-deploy trust for every crate in the graph that he alone publishes. That is the six above plus anyhow, itoa, prettyplease, serde_bytes, serde_json and unicode-ident, which until now passed only on version-pinned exemptions. The nine exemptions this makes redundant are removed. The new entries end 2027-05-30, the same date as the existing
[[trusted]]entries, so all of them renew together.Pre-exempt the rest of the pending update. These crates have no peer-trusted publisher and no imported audit for the new version:
tempfile, a build dependency, onto itcbindgen 0.29.4, xxhash-rust 0.8.18, zeroize 1.9.0 and zeroize_derive 1.5.0 are not in this lock yet, and this lock does not need the r-efi raise yet. So
cargo vetwarns about them, andcargo vet prunewould remove the four and lower r-efi back to safe-to-run. Don't prune until the update lands.getrandom 0.3.4 is already in this lock, and prune keeps its exemption. Together with the imported isrg and bytecode-alliance delta audits, it now also vets getrandom 0.4.2.
imports.lockis the store ascargo vet trustrewrote it: publisher records for the newly trusted versions and the peers' current audits.Keep a human on serde_json updates (
renovate.json). serde_json is a dev-dependency, and the inheritedrust-dev-depsrule automerges dev-dependency updates once checks pass. Until now the vet check went red on every new serde_json version, which kept those updates from automerging. With dtolnay trusted, a serde_json release, and the serde_core it resolves (a runtime dependency), would otherwise reachmainwith no human review. The new rule setsautomerge: falsefor serde_json. Renovate automerges a group only when every update in it automerges, so arust-dev-depsgroup that carries a serde_json update waits for a human too. serde_json is the only direct dev-dependency among the trusted crates. The others arrive through the non-major group or lock-file maintenance, and neither automerges.No criteria are relaxed, and the workflow is unchanged.
Verification
This was checked with cargo-vet 0.10.2, the version CI installs. It was run as plain
cargo vet, not--locked, as CI runs it. The update was applied locally withcargo update -p <crate> --precise <ver>for thiserror 2.0.21, serde 1.0.229, xxhash-rust 0.8.18, zeroize 1.9.0 and cbindgen 0.29.4:Vetting Succeeded (75 fully audited, 5 partially audited, 84 exempted).main's store, same lock:Vetting Failed!with 12 unvetted (the six dtolnay crates plus the six in the table).cargo vet explain-auditon each of the 12 shows the intended path: a trusted entry (published by dtolnay) or the local exemption.xxhash-rust:0.8.17 missing ["safe-to-deploy"].cargo vetandcargo vet --lockedboth pass (91 fully audited, 5 partially audited, 87 exempted).What still needs a hand-written entry
A crate without a peer-trusted publisher still needs an entry on each new version, unless an imported feed audits the delta first. The pinned exemptions above give such a delta a base to chain from:
The dtolnay entries need renewing before 2027-05-30, along with the existing trust entries. They also do not cover a release published through a trusted-publishing identity instead of his user account.
Closes LAB-6649
Summary
This PR adjusts supply-chain trust configuration for crates published by David Tolnay (dtolnay) and adds a Renovate safeguard for
serde_json.Changes
supply-chain/audits.toml2027-09-30to2027-05-30, matching the end date already used by other trusted entries in the file.[[trusted.*]]entries includeserde,serde_bytes,serde_core,serde_derive,serde_json,syn,thiserror,thiserror-impl,unicode-ident, and several others earlier in the file.safe-to-deploy) and start dates are unchanged.renovate.jsoncargomanager that setsautomerge: falseforserde_json.audits.toml,cargo vetaccepts newserde_jsonreleases without per-version review.serde_jsonalso resolvesserde_core, which is a runtime dependency. Everyserde_jsonupdate therefore requires a manual merge.Impact
serde_jsonupdates are no longer merged automatically. This keeps human oversight on a runtime-relevant dependency thatcargo vetwould otherwise pass unreviewed.