From 0583792845af23a8285e9ac4492a2b87ea473859 Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Wed, 30 Sep 2026 22:37:38 +1000 Subject: [PATCH 1/2] chore(supply-chain): trust dtolnay, whom the imported peers trust, and pre-exempt the rest (LAB-6649) Every dependency update adds versions that no imported audit or version-pinned exemption covers yet, so `cargo vet` fails on each one. The imported isrg, mozilla and bytecode-alliance feeds trust David Tolnay as a publisher, and `cargo vet` suggests trusting him for the failing serde, serde_core, serde_derive, syn, thiserror and thiserror-impl releases. The existing [[trusted]] entries follow the same rule for other publishers. `cargo vet trust --all dtolnay` records safe-to-deploy trust, ending one year out, for every crate in the graph that he alone publishes. That is those six plus anyhow, itoa, prettyplease, serde_bytes, serde_json and unicode-ident, which until now passed only on version-pinned exemptions. Their new releases now pass without a per-version entry. The nine exemptions that trust makes redundant are removed. The other crates in the pending update have no peer-trusted publisher and no imported audit for the new version, so they get version-pinned exemptions: xxhash-rust 0.8.18, zeroize 1.9.0, zeroize_derive 1.5.0, cbindgen 0.29.4 and getrandom 0.3.4. The existing r-efi 5.3.0 exemption is raised from safe-to-run to safe-to-deploy. cbindgen 0.29.4 moves tempfile, a build dependency, onto getrandom 0.3.4, which pulls r-efi 5.3.0 up with it. None of those versions is in this lock yet, so `cargo vet` warns that `cargo vet prune` would remove them. Do not prune until the update lands. `imports.lock` is the store as `cargo vet trust` rewrote it: publisher records for the newly trusted versions and the peers' current audits. --- supply-chain/audits.toml | 72 +++++++++++++++++++++++++++++++++++++++ supply-chain/config.toml | 58 ++++++++++++------------------- supply-chain/imports.lock | 69 +++++++++++++++++++++++++++++++++++++ 3 files changed, 162 insertions(+), 37 deletions(-) diff --git a/supply-chain/audits.toml b/supply-chain/audits.toml index 5776af5..4d77b43 100644 --- a/supply-chain/audits.toml +++ b/supply-chain/audits.toml @@ -3,6 +3,12 @@ [audits] +[[trusted.anyhow]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-10-05" +end = "2027-09-30" + [[trusted.half]] criteria = "safe-to-run" user-id = 3416 # Kathryn Long (starkat99) @@ -15,6 +21,12 @@ user-id = 6825 # Dan Gohman (sunfishcode) start = "2022-01-22" end = "2027-05-30" +[[trusted.itoa]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-05-02" +end = "2027-09-30" + [[trusted.linux-raw-sys]] criteria = "safe-to-deploy" user-id = 6825 # Dan Gohman (sunfishcode) @@ -27,6 +39,12 @@ user-id = 189 # Andrew Gallant (BurntSushi) start = "2019-07-07" end = "2027-05-30" +[[trusted.prettyplease]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2022-01-04" +end = "2027-09-30" + [[trusted.rayon]] criteria = "safe-to-run" user-id = 539 # Josh Stone (cuviper) @@ -45,6 +63,60 @@ user-id = 6825 # Dan Gohman (sunfishcode) start = "2021-10-29" end = "2027-05-30" +[[trusted.serde]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-03-01" +end = "2027-09-30" + +[[trusted.serde_bytes]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-02-25" +end = "2027-09-30" + +[[trusted.serde_core]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2025-09-13" +end = "2027-09-30" + +[[trusted.serde_derive]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-03-01" +end = "2027-09-30" + +[[trusted.serde_json]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-02-28" +end = "2027-09-30" + +[[trusted.syn]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-03-01" +end = "2027-09-30" + +[[trusted.thiserror]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-10-09" +end = "2027-09-30" + +[[trusted.thiserror-impl]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2019-10-09" +end = "2027-09-30" + +[[trusted.unicode-ident]] +criteria = "safe-to-deploy" +user-id = 3618 # David Tolnay (dtolnay) +start = "2021-10-02" +end = "2027-09-30" + [[trusted.walkdir]] criteria = "safe-to-deploy" user-id = 189 # Andrew Gallant (BurntSushi) diff --git a/supply-chain/config.toml b/supply-chain/config.toml index e2d4c4a..a06e7a2 100644 --- a/supply-chain/config.toml +++ b/supply-chain/config.toml @@ -57,10 +57,6 @@ criteria = "safe-to-deploy" version = "3.0.11" criteria = "safe-to-deploy" -[[exemptions.anyhow]] -version = "1.0.102" -criteria = "safe-to-deploy" - [[exemptions.blake2]] version = "0.10.6" criteria = "safe-to-run" @@ -69,6 +65,10 @@ criteria = "safe-to-run" version = "0.29.2" criteria = "safe-to-deploy" +[[exemptions.cbindgen]] +version = "0.29.4" +criteria = "safe-to-deploy" + [[exemptions.cc]] version = "1.2.62" criteria = "safe-to-deploy" @@ -153,6 +153,10 @@ criteria = "safe-to-deploy" version = "0.2.17" criteria = "safe-to-deploy" +[[exemptions.getrandom]] +version = "0.3.4" +criteria = "safe-to-deploy" + [[exemptions.getrandom]] version = "0.4.2" criteria = "safe-to-deploy" @@ -185,10 +189,6 @@ criteria = "safe-to-deploy" version = "1.70.2" criteria = "safe-to-deploy" -[[exemptions.itoa]] -version = "1.0.18" -criteria = "safe-to-deploy" - [[exemptions.js-sys]] version = "0.3.98" criteria = "safe-to-deploy" @@ -229,17 +229,13 @@ criteria = "safe-to-run" version = "0.6.2" criteria = "safe-to-deploy" -[[exemptions.prettyplease]] -version = "0.2.37" -criteria = "safe-to-deploy" - [[exemptions.proptest]] version = "1.11.0" criteria = "safe-to-run" [[exemptions.r-efi]] version = "5.3.0" -criteria = "safe-to-run" +criteria = "safe-to-deploy" [[exemptions.r-efi]] version = "6.0.0" @@ -266,14 +262,6 @@ criteria = "safe-to-run" version = "1.0.28" criteria = "safe-to-deploy" -[[exemptions.serde_bytes]] -version = "0.11.19" -criteria = "safe-to-deploy" - -[[exemptions.serde_json]] -version = "1.0.149" -criteria = "safe-to-deploy" - [[exemptions.serde_spanned]] version = "1.1.1" criteria = "safe-to-deploy" @@ -282,22 +270,10 @@ criteria = "safe-to-deploy" version = "0.4.12" criteria = "safe-to-deploy" -[[exemptions.syn]] -version = "2.0.117" -criteria = "safe-to-deploy" - [[exemptions.tempfile]] version = "3.27.0" criteria = "safe-to-deploy" -[[exemptions.thiserror]] -version = "2.0.18" -criteria = "safe-to-deploy" - -[[exemptions.thiserror-impl]] -version = "2.0.18" -criteria = "safe-to-deploy" - [[exemptions.toml]] version = "0.9.12+spec-1.1.0" criteria = "safe-to-deploy" @@ -318,10 +294,6 @@ criteria = "safe-to-deploy" version = "1.20.0" criteria = "safe-to-deploy" -[[exemptions.unicode-ident]] -version = "1.0.24" -criteria = "safe-to-deploy" - [[exemptions.untrusted]] version = "0.9.0" criteria = "safe-to-deploy" @@ -411,6 +383,10 @@ version = "0.8.15" criteria = "safe-to-deploy" notes = "xxHash3 non-cryptographic hash - 36 GB/s integrity checking for compressed data." +[[exemptions.xxhash-rust]] +version = "0.8.18" +criteria = "safe-to-deploy" + [[exemptions.zerocopy]] version = "0.8.48" criteria = "safe-to-run" @@ -419,10 +395,18 @@ criteria = "safe-to-run" version = "0.8.48" criteria = "safe-to-run" +[[exemptions.zeroize]] +version = "1.9.0" +criteria = "safe-to-deploy" + [[exemptions.zeroize_derive]] version = "1.4.3" criteria = "safe-to-deploy" +[[exemptions.zeroize_derive]] +version = "1.5.0" +criteria = "safe-to-deploy" + [[exemptions.zmij]] version = "1.0.21" criteria = "safe-to-deploy" diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock index 50ca26f..7b7e546 100644 --- a/supply-chain/imports.lock +++ b/supply-chain/imports.lock @@ -1,6 +1,13 @@ # cargo-vet imports lock +[[publisher.anyhow]] +version = "1.0.102" +when = "2026-02-20" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.bumpalo]] version = "3.20.2" when = "2026-02-19" @@ -22,6 +29,13 @@ user-id = 6825 user-login = "sunfishcode" user-name = "Dan Gohman" +[[publisher.itoa]] +version = "1.0.18" +when = "2026-03-20" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.linux-raw-sys]] version = "0.12.1" when = "2025-12-23" @@ -36,6 +50,13 @@ user-id = 189 user-login = "BurntSushi" user-name = "Andrew Gallant" +[[publisher.prettyplease]] +version = "0.2.37" +when = "2025-08-19" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.rayon]] version = "1.12.0" when = "2026-04-14" @@ -57,6 +78,48 @@ user-id = 6825 user-login = "sunfishcode" user-name = "Dan Gohman" +[[publisher.serde_bytes]] +version = "0.11.19" +when = "2025-09-15" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.serde_json]] +version = "1.0.149" +when = "2026-01-06" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.syn]] +version = "2.0.117" +when = "2026-02-20" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.thiserror]] +version = "2.0.18" +when = "2026-01-18" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.thiserror-impl]] +version = "2.0.18" +when = "2026-01-18" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + +[[publisher.unicode-ident]] +version = "1.0.24" +when = "2026-02-16" +user-id = 3618 +user-login = "dtolnay" +user-name = "David Tolnay" + [[publisher.unicode-xid]] version = "0.2.6" when = "2024-09-19" @@ -341,6 +404,12 @@ criteria = "safe-to-deploy" delta = "0.9.15 -> 0.9.18" notes = "Nontrivial update but mostly around dependencies and how `unsafe` code is managed. Everything looks the same shape as before." +[[audits.bytecode-alliance.audits.crossbeam-epoch]] +who = "Alex Crichton " +criteria = "safe-to-deploy" +delta = "0.9.18 -> 0.9.20" +notes = "Minor updates, nothing out of place." + [[audits.bytecode-alliance.audits.errno]] who = "Dan Gohman " criteria = "safe-to-deploy" From 12d07601005fe0739be93d4b5746c2c07002ae3f Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Wed, 30 Sep 2026 23:02:09 +1000 Subject: [PATCH 2/2] chore(renovate): keep a human on serde_json updates now that its publisher is trusted (LAB-6649) With dtolnay trusted, `cargo vet` passes each new serde_json release without a per-version entry. serde_json is a dev-dependency, and the inherited rust-dev-deps rule automerges dev-dependency updates once checks pass. Until now the vet check went red on every new version, which kept those updates from automerging. Without this rule, a serde_json release, and the serde_core it resolves (a runtime dependency), would reach main with no human review. The rule sets automerge to false for serde_json. Renovate automerges a group only when every update in it automerges, so a rust-dev-deps group that carries a serde_json update waits for a human as well. serde_json is the only direct dev-dependency among the trusted crates. The others arrive through the non-major group or lock-file maintenance, and neither automerges. The new [[trusted]] entries now end 2027-05-30, the same date as the existing entries, so all trust entries renew together. A correction to the previous commit message: getrandom 0.3.4 is already in this lock, reached through a dev-dependency. Its new safe-to-deploy exemption is kept by `cargo vet prune`, and with the imported delta audits it now also vets getrandom 0.4.2. Only cbindgen 0.29.4, xxhash-rust 0.8.18, zeroize 1.9.0, zeroize_derive 1.5.0 and the r-efi raise wait on the pending update. The dtolnay trust is publisher-wide: the peers trust him as a publisher, and some of their per-crate entries for him have lapsed. --- renovate.json | 6 ++++++ supply-chain/audits.toml | 24 ++++++++++++------------ 2 files changed, 18 insertions(+), 12 deletions(-) diff --git a/renovate.json b/renovate.json index bc8c38e..f20034a 100644 --- a/renovate.json +++ b/renovate.json @@ -24,6 +24,12 @@ "matchUpdateTypes": ["patch"], "groupName": null, "dependencyDashboardApproval": true + }, + { + "description": "serde_json never automerges. Its publisher is trusted in supply-chain/audits.toml, so cargo vet passes its new releases with no per-version review, and the serde_core it resolves is a runtime dependency. A human merges every serde_json update.", + "matchManagers": ["cargo"], + "matchPackageNames": ["serde_json"], + "automerge": false } ] } diff --git a/supply-chain/audits.toml b/supply-chain/audits.toml index 4d77b43..263d9a5 100644 --- a/supply-chain/audits.toml +++ b/supply-chain/audits.toml @@ -7,7 +7,7 @@ criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-10-05" -end = "2027-09-30" +end = "2027-05-30" [[trusted.half]] criteria = "safe-to-run" @@ -25,7 +25,7 @@ end = "2027-05-30" criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-05-02" -end = "2027-09-30" +end = "2027-05-30" [[trusted.linux-raw-sys]] criteria = "safe-to-deploy" @@ -43,7 +43,7 @@ end = "2027-05-30" criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2022-01-04" -end = "2027-09-30" +end = "2027-05-30" [[trusted.rayon]] criteria = "safe-to-run" @@ -67,55 +67,55 @@ end = "2027-05-30" criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-03-01" -end = "2027-09-30" +end = "2027-05-30" [[trusted.serde_bytes]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-02-25" -end = "2027-09-30" +end = "2027-05-30" [[trusted.serde_core]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2025-09-13" -end = "2027-09-30" +end = "2027-05-30" [[trusted.serde_derive]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-03-01" -end = "2027-09-30" +end = "2027-05-30" [[trusted.serde_json]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-02-28" -end = "2027-09-30" +end = "2027-05-30" [[trusted.syn]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-03-01" -end = "2027-09-30" +end = "2027-05-30" [[trusted.thiserror]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-10-09" -end = "2027-09-30" +end = "2027-05-30" [[trusted.thiserror-impl]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2019-10-09" -end = "2027-09-30" +end = "2027-05-30" [[trusted.unicode-ident]] criteria = "safe-to-deploy" user-id = 3618 # David Tolnay (dtolnay) start = "2021-10-02" -end = "2027-09-30" +end = "2027-05-30" [[trusted.walkdir]] criteria = "safe-to-deploy"