Skip to content

fix: update rand to resolve GHSA-cq8v-f236-94qc#4

Draft
dannyneira wants to merge 1 commit into
mainfrom
independabot/rand-ghsa-cq8v-f236-94qc
Draft

fix: update rand to resolve GHSA-cq8v-f236-94qc#4
dannyneira wants to merge 1 commit into
mainfrom
independabot/rand-ghsa-cq8v-f236-94qc

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

  • Updates transitive rand lockfile entries from 0.8.5 to 0.8.6 and 0.9.2 to 0.9.3
  • Resolves GHSA-cq8v-f236-94qc for both vulnerable locked rand ranges
  • No manifest changes or dependency overrides were needed

Vulnerability details

Verification

  • cargo fmt --check
  • cargo check
  • cargo test
  • cargo clippy --all-targets --all-features -- -D warnings
  • cargo audit --json no longer reports a rand advisory; unrelated existing advisories remain for bytes, quinn-proto, rsa, and rustls-webpki.

Conversation: https://staging.warp.dev/conversation/e2c93a7e-043b-483a-b32b-77bd62fef864
Run: https://oz.staging.warp.dev/runs/019e7ec3-80f1-74b9-80ae-99d413bbc9e0

Co-Authored-By: Oz oz-agent@warp.dev
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira requested a review from bholmesdev May 31, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants