Skip to content

Conversation

@tullom
Copy link
Contributor

@tullom tullom commented Jan 22, 2026

The cargo-vet CI job is currently failing with 36 unvetted dependencies with a note These audits may have been made with a more recent version of cargo-vet. Updating to the latest version of cargo-vet gets rid of these unvetted dependencies as it seems the vetting was done with cargo-vet@0.10.2. Why this is not a breaking minor change is beyond me.

Vetting Failed!                                                                                                                                                                                                                                 

42 unvetted dependencies:
  aho-corasick:1.1.3 missing ["safe-to-deploy"]
  anyhow:1.0.99 missing ["safe-to-deploy"]
  cc:1.2.33 missing ["safe-to-deploy"]
  encoding_rs:0.8.35 missing ["safe-to-deploy"]
  libc:0.2.175 missing ["safe-to-deploy"]
  loom:0.7.2 missing ["safe-to-deploy"]
  memchr:2.7.5 missing ["safe-to-deploy"]
  paste:1.0.15 missing ["safe-to-deploy"]
  proc-macro2:1.0.101 missing ["safe-to-deploy"]
  regex-automata:0.4.13 missing ["safe-to-deploy"]
  ryu:1.0.20 missing ["safe-to-deploy"]
  scoped-tls:1.0.1 missing ["safe-to-deploy"]
  serde_json:1.0.143 missing ["safe-to-deploy"]
  syn:1.0.109 missing ["safe-to-deploy"]
  syn:2.0.106 missing ["safe-to-deploy"]
  thiserror:1.0.69 missing ["safe-to-deploy"]
  thiserror:2.0.16 missing ["safe-to-deploy"]
  thiserror-impl:1.0.69 missing ["safe-to-deploy"]
  thiserror-impl:2.0.16 missing ["safe-to-deploy"]
  unicode-segmentation:1.12.0 missing ["safe-to-deploy"]
  unicode-width:0.1.14 missing ["safe-to-deploy"]
  windows:0.61.3 missing ["safe-to-deploy"]
  windows-collections:0.2.0 missing ["safe-to-deploy"]
  windows-core:0.61.2 missing ["safe-to-deploy"]
  windows-future:0.2.1 missing ["safe-to-deploy"]
  windows-implement:0.60.0 missing ["safe-to-deploy"]
  windows-interface:0.59.1 missing ["safe-to-deploy"]
  windows-numerics:0.2.0 missing ["safe-to-deploy"]
  windows-result:0.3.4 missing ["safe-to-deploy"]
  windows-strings:0.4.2 missing ["safe-to-deploy"]
  windows-sys:0.52.0 missing ["safe-to-deploy"]
  windows-sys:0.59.0 missing ["safe-to-run"]
  windows-targets:0.52.6 missing ["safe-to-deploy"]
  windows-threading:0.1.0 missing ["safe-to-deploy"]
  windows_aarch64_gnullvm:0.52.6 missing ["safe-to-deploy"]
  windows_aarch64_msvc:0.52.6 missing ["safe-to-deploy"]
  windows_i686_gnu:0.52.6 missing ["safe-to-deploy"]
  windows_i686_gnullvm:0.52.6 missing ["safe-to-deploy"]
  windows_i686_msvc:0.52.6 missing ["safe-to-deploy"]
  windows_x86_64_gnu:0.52.6 missing ["safe-to-deploy"]
  windows_x86_64_gnullvm:0.52.6 missing ["safe-to-deploy"]
  windows_x86_64_msvc:0.52.6 missing ["safe-to-deploy"]

@tullom tullom self-assigned this Jan 22, 2026
@tullom tullom requested a review from a team as a code owner January 22, 2026 17:56
@tullom tullom added the bug Something isn't working label Jan 22, 2026
@github-actions
Copy link

github-actions bot commented Jan 22, 2026

Cargo Vet Audit Passed

cargo vet has passed in this PR. No new unvetted dependencies were found.

@github-actions github-actions bot added the cargo vet PRs pending auditor review label Jan 22, 2026
@kurtjd
Copy link
Contributor

kurtjd commented Jan 22, 2026

Looks like we need to bump toolchain from 1.88 to at least 1.89? Maybe good to just bump it to latest?

@tullom
Copy link
Contributor Author

tullom commented Jan 22, 2026

Looks like we need to bump toolchain from 1.88 to at least 1.89? Maybe good to just bump it to latest?

Yep, pushed it out with a cargo +stable install cargo-vet... just as you commented 😛

@tullom tullom requested a review from a team as a code owner January 22, 2026 18:06
@tullom tullom requested review from jeffglaum and jerrysxie January 22, 2026 18:06
Copy link
Contributor

@kurtjd kurtjd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is interesting. cargo-vet won't honor audits made by a different version of itself? How does it track this? Weird...

@tullom tullom moved this to In review in Embedded Controller Jan 22, 2026
@RobertZ2011 RobertZ2011 merged commit 829f5da into OpenDevicePartnership:v0.2.0 Jan 22, 2026
14 checks passed
@github-project-automation github-project-automation bot moved this from In review to Done in Embedded Controller Jan 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working cargo vet PRs pending auditor review

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants