diff --git a/renovate.json b/renovate.json index bc8c38e..f20034a 100644 --- a/renovate.json +++ b/renovate.json @@ -24,6 +24,12 @@ "matchUpdateTypes": ["patch"], "groupName": null, "dependencyDashboardApproval": true + }, + { + "description": "serde_json never automerges. Its publisher is trusted in supply-chain/audits.toml, so cargo vet passes its new releases with no per-version review, and the serde_core it resolves is a runtime dependency. A human merges every serde_json update.", + "matchManagers": ["cargo"], + "matchPackageNames": ["serde_json"], + "automerge": false } ] } diff --git a/supply-chain/audits.toml b/supply-chain/audits.toml index 5776af5..263d9a5 100644 --- a/supply-chain/audits.toml +++ b/supply-chain/audits.toml @@ -3,6 +3,12 @@ [audits] +[[trusted.anyhow]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-10-05" +end = "2027-05-30" + [[trusted.half]] criteria = "safe-to-run" user-id = 3416 # Kathryn Long (starkat99) @@ -15,6 +21,12 @@ user-id = 6825 # Dan Gohman (sunfishcode) start = "2022-01-22" end = "2027-05-30" +[[trusted.itoa]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-05-02" +end = "2027-05-30" + [[trusted.linux-raw-sys]] criteria = "safe-to-deploy" user-id = 6825 # Dan Gohman (sunfishcode) @@ -27,6 +39,12 @@ user-id = 189 # Andrew Gallant (BurntSushi) start = "2019-07-07" end = "2027-05-30" +[[trusted.prettyplease]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2022-01-04" +end = "2027-05-30" + [[trusted.rayon]] criteria = "safe-to-run" user-id = 539 # Josh Stone (cuviper) @@ -45,6 +63,60 @@ user-id = 6825 # Dan Gohman (sunfishcode) start = "2021-10-29" end = "2027-05-30" +[[trusted.serde]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-03-01" +end = "2027-05-30" + +[[trusted.serde_bytes]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-02-25" +end = "2027-05-30" + +[[trusted.serde_core]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2025-09-13" +end = "2027-05-30" + +[[trusted.serde_derive]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-03-01" +end = "2027-05-30" + +[[trusted.serde_json]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-02-28" +end = "2027-05-30" + +[[trusted.syn]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-03-01" +end = "2027-05-30" + +[[trusted.thiserror]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-10-09" +end = "2027-05-30" + +[[trusted.thiserror-impl]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-10-09" +end = "2027-05-30" + +[[trusted.unicode-ident]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2021-10-02" +end = "2027-05-30" + [[trusted.walkdir]] criteria = "safe-to-deploy" user-id = 189 # Andrew Gallant (BurntSushi) diff --git a/supply-chain/config.toml b/supply-chain/config.toml index e2d4c4a..a06e7a2 100644 --- a/supply-chain/config.toml +++ b/supply-chain/config.toml @@ -57,10 +57,6 @@ criteria = "safe-to-deploy" version = "3.0.11" criteria = "safe-to-deploy" -[[exemptions.anyhow]] -version = "1.0.102" -criteria = "safe-to-deploy" - [[exemptions.blake2]] version = "0.10.6" criteria = "safe-to-run" @@ -69,6 +65,10 @@ criteria = "safe-to-run" version = "0.29.2" criteria = "safe-to-deploy" +[[exemptions.cbindgen]] +version = "0.29.4" +criteria = "safe-to-deploy" + [[exemptions.cc]] version = "1.2.62" criteria = "safe-to-deploy" @@ -153,6 +153,10 @@ criteria = "safe-to-deploy" version = "0.2.17" criteria = "safe-to-deploy" +[[exemptions.getrandom]] +version = "0.3.4" +criteria = "safe-to-deploy" + [[exemptions.getrandom]] version = "0.4.2" criteria = "safe-to-deploy" @@ -185,10 +189,6 @@ criteria = "safe-to-deploy" version = "1.70.2" criteria = "safe-to-deploy" -[[exemptions.itoa]] -version = "1.0.18" -criteria = "safe-to-deploy" - [[exemptions.js-sys]] version = "0.3.98" criteria = "safe-to-deploy" @@ -229,17 +229,13 @@ criteria = "safe-to-run" version = "0.6.2" criteria = "safe-to-deploy" -[[exemptions.prettyplease]] -version = "0.2.37" -criteria = "safe-to-deploy" - [[exemptions.proptest]] version = "1.11.0" criteria = "safe-to-run" [[exemptions.r-efi]] version = "5.3.0" -criteria = "safe-to-run" +criteria = "safe-to-deploy" [[exemptions.r-efi]] version = "6.0.0" @@ -266,14 +262,6 @@ criteria = "safe-to-run" version = "1.0.28" criteria = "safe-to-deploy" -[[exemptions.serde_bytes]] -version = "0.11.19" -criteria = "safe-to-deploy" - -[[exemptions.serde_json]] -version = "1.0.149" -criteria = "safe-to-deploy" - [[exemptions.serde_spanned]] version = "1.1.1" criteria = "safe-to-deploy" @@ -282,22 +270,10 @@ criteria = "safe-to-deploy" version = "0.4.12" criteria = "safe-to-deploy" -[[exemptions.syn]] -version = "2.0.117" -criteria = "safe-to-deploy" - [[exemptions.tempfile]] version = "3.27.0" criteria = "safe-to-deploy" -[[exemptions.thiserror]] -version = "2.0.18" -criteria = "safe-to-deploy" - -[[exemptions.thiserror-impl]] -version = "2.0.18" -criteria = "safe-to-deploy" - [[exemptions.toml]] version = "0.9.12+spec-1.1.0" criteria = "safe-to-deploy" @@ -318,10 +294,6 @@ criteria = "safe-to-deploy" version = "1.20.0" criteria = "safe-to-deploy" -[[exemptions.unicode-ident]] -version = "1.0.24" -criteria = "safe-to-deploy" - [[exemptions.untrusted]] version = "0.9.0" criteria = "safe-to-deploy" @@ -411,6 +383,10 @@ version = "0.8.15" criteria = "safe-to-deploy" notes = "xxHash3 non-cryptographic hash - 36 GB/s integrity checking for compressed data." +[[exemptions.xxhash-rust]] +version = "0.8.18" +criteria = "safe-to-deploy" + [[exemptions.zerocopy]] version = "0.8.48" criteria = "safe-to-run" @@ -419,10 +395,18 @@ criteria = "safe-to-run" version = "0.8.48" criteria = "safe-to-run" +[[exemptions.zeroize]] +version = "1.9.0" +criteria = "safe-to-deploy" + [[exemptions.zeroize_derive]] version = "1.4.3" criteria = "safe-to-deploy" +[[exemptions.zeroize_derive]] +version = "1.5.0" +criteria = "safe-to-deploy" + [[exemptions.zmij]] version = "1.0.21" criteria = "safe-to-deploy" diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock index 50ca26f..7b7e546 100644 --- a/supply-chain/imports.lock +++ b/supply-chain/imports.lock @@ -1,6 +1,13 @@ # cargo-vet imports lock +[[publisher.anyhow]] +version = "1.0.102" +when = "2026-02-20" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.bumpalo]] version = "3.20.2" when = "2026-02-19" @@ -22,6 +29,13 @@ user-id = 6825 user-login = "sunfishcode" user-name = "Dan Gohman" +[[publisher.itoa]] +version = "1.0.18" +when = "2026-03-20" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.linux-raw-sys]] version = "0.12.1" when = "2025-12-23" @@ -36,6 +50,13 @@ user-id = 189 user-login = "BurntSushi" user-name = "Andrew Gallant" +[[publisher.prettyplease]] +version = "0.2.37" +when = "2025-08-19" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.rayon]] version = "1.12.0" when = "2026-04-14" @@ -57,6 +78,48 @@ user-id = 6825 user-login = "sunfishcode" user-name = "Dan Gohman" +[[publisher.serde_bytes]] +version = "0.11.19" +when = "2025-09-15" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.serde_json]] +version = "1.0.149" +when = "2026-01-06" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.syn]] +version = "2.0.117" +when = "2026-02-20" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.thiserror]] +version = "2.0.18" +when = "2026-01-18" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.thiserror-impl]] +version = "2.0.18" +when = "2026-01-18" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.unicode-ident]] +version = "1.0.24" +when = "2026-02-16" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.unicode-xid]] version = "0.2.6" when = "2024-09-19" @@ -341,6 +404,12 @@ criteria = "safe-to-deploy" delta = "0.9.15 -> 0.9.18" notes = "Nontrivial update but mostly around dependencies and how `unsafe` code is managed. Everything looks the same shape as before." +[[audits.bytecode-alliance.audits.crossbeam-epoch]] +who = "Alex Crichton " +criteria = "safe-to-deploy" +delta = "0.9.18 -> 0.9.20" +notes = "Minor updates, nothing out of place." + [[audits.bytecode-alliance.audits.errno]] who = "Dan Gohman " criteria = "safe-to-deploy"