Commit d00a38c
fix(deps): bump event-listener to 5.4.2 to clear RUSTSEC-2026-0221
`cargo audit --deny warnings` was failing the blocking security gate on
event-listener 5.4.1, which unconditionally implements Send/Sync for
StackSlot and lets a !Send tag cross a thread boundary (unsound,
memory-corruption/thread-safety).
Only consumer is sqlx-core 0.8.6 on a ^5 requirement, so the patch bump
resolves without touching sqlx. 5.4.2 is the advisory's patched floor
(patched = [">= 5.4.2"]). The bump also drops concurrent-queue entirely
from the graph -- nothing else depended on it.
Verified: cargo audit with the workflow's documented ignore list exits 0,
cargo check --all-targets clean, 555 server unit tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>1 parent 228b98b commit d00a38c
1 file changed
Lines changed: 2 additions & 12 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments