Skip to content

fix(deps): cargo update on release/0.5.z for CVE-2026-93657 - #2751

Open
ruromero wants to merge 1 commit into
guacsec:release/0.5.zfrom
ruromero:TC-6644-v2
Open

ruromero wants to merge 1 commit into
guacsec:release/0.5.zfrom
ruromero:TC-6644-v2

Conversation

@ruromero

@ruromero ruromero commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Full cargo update on release/0.5.z — pulls hickory-resolver 0.26.3 (fixes CVE-2026-93657 DNSSEC validation bypass) and updates all compatible dependencies
  • Pin csaf-rs to rev 63ac9e19 to prevent drift to packageurl 0.7 (which breaks 32 analysis tests due to qualifier encoding changes)

Supersedes PR #2724.

Verified locally

  • cargo check — pass
  • cargo fmt --check — pass
  • cargo clippy --workspace -- -D warnings — pass
  • cargo test -p trustify-common — 84/84 pass
  • cargo test -p trustify-module-analysis — 303/303 pass

Test plan

Implements TC-6644

🤖 Generated with Claude Code

Summary by Sourcery

Refresh release/0.5.z dependencies and pin csaf-rs while incorporating the DNSSEC security fix.

Bug Fixes:

  • Update dependencies to include hickory-resolver 0.26.3, addressing the CVE-2026-93657 DNSSEC validation bypass.

Enhancements:

  • Refresh the release branch dependency lockfile and pin csaf-rs to a known revision to maintain compatible package URL qualifier behavior.

@sourcery-ai

sourcery-ai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This PR performs a full Cargo dependency refresh on release/0.5.z, including hickory-resolver 0.26.3 to address CVE-2026-93657, while pinning csaf-rs to a tested revision to avoid packageurl compatibility regressions. Local formatting, linting, compilation, and targeted common and analysis test suites pass; CI validation remains pending.

File-Level Changes

Change Details Files
Refresh the locked dependency graph to incorporate the DNSSEC vulnerability fix and compatible upstream updates.
  • Run a full Cargo dependency update on the release branch.
  • Upgrade hickory-resolver to 0.26.3 and record the resulting transitive lockfile changes.
  • Review compatibility impacts from the broad lockfile refresh, particularly security-sensitive DNS and resolver dependencies.
Cargo.lock
Stabilize the CSAF dependency at a known revision to preserve analysis behavior.
  • Replace the floating csaf-rs main-branch reference with commit 63ac9e19d881cbf1808de38b6849635cda19931d.
  • Prevent packageurl 0.7 drift and its qualifier-encoding changes that previously broke analysis tests.
Cargo.toml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

sourcery-ai[bot]
sourcery-ai Bot previously approved these changes Oct 9, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Fixed security issues:

  • hickory-resolver (link)

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Run full `cargo update` to pull in hickory-resolver 0.26.3 (fixes
CVE-2026-93657 DNSSEC validation bypass) and update all compatible
dependencies.

Pin csaf-rs to rev 63ac9e19 to prevent cargo update from drifting
to a newer rev that requires packageurl 0.7 (breaking 32 analysis
tests due to qualifier encoding changes).

Verified locally:
- cargo check: pass
- cargo fmt --check: pass
- cargo clippy -D warnings: pass
- cargo test -p trustify-common: 84/84 pass
- cargo test -p trustify-module-analysis: 303/303 pass

Implements TC-6644

Assisted-by: Claude Code
@sourcery-ai
sourcery-ai Bot dismissed their stale review October 9, 2026 11:29

Sourcery withdrew this approval because the latest commits introduced blocking findings.

@ruromero
ruromero enabled auto-merge October 9, 2026 14:28
@ruromero
ruromero requested a review from a team October 9, 2026 14:28

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant