docs(deny): tighten + correct the quick-xml ignore note#176
Merged
Conversation
The quick-xml ignore block landed in #171/#175 was ~12 comment lines with heavy ALL-CAPS emphasis and reason strings that duplicated the comment — inconsistent with the file's other ignore groups (hickory/gtk are 3-4 tight lines with concise one-line reasons). Tighten to the same style; no facts lost (trigger = a zbus_xml 5.x release on quick-xml 0.41, merged-but-unreleased upstream, no gpui bump, 6.0 caveat all retained). Comment-only; `cargo deny check advisories` stays green.
A parallel investigation (+ the upstream nudge z-galaxy/zbus#1837) surfaced that these advisories fire on TWO sub-0.41 quick-xml copies, not one: - 0.39.4 — runtime, via the gpui Linux AT-SPI stack (fixed by a zbus_xml 5.x) - 0.30.0 — a *build* dep of xcb 1.7.0 (X11 protocol XML; trusted input, no runtime surface, and no released xcb uses quick-xml >=0.41) The advisories have no lower bound, so both match; cargo-deny just collapses the report to the 0.39.4 node. So the earlier "drop the two ignores once zbus_xml ships" was over-optimistic — after `cargo update -p zbus_xml` the xcb 0.30.0 build-dep still fires. Correct the note to NARROW (not delete) the entries to the xcb residual, and reference the upstream release nudge.
hellno
force-pushed
the
hellno/deny-slop-trim
branch
from
July 2, 2026 16:48
59fb115 to
42116bd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two commits:
1. Trim the slop (/remove-slop). The block from #171/#175 was ~12 comment lines with heavy ALL-CAPS emphasis and
reasonstrings that duplicated the comment — inconsistent with the file's other ignore groups (hickory/gtk: 3-4 tight lines). Tightened to the house style.2. Correct a factual error. A parallel investigation (which also filed the upstream release nudge z-galaxy/zbus#1837) found these advisories fire on two sub-0.41 quick-xml copies, not one:
0.39.4— runtime, via the gpui Linux AT-SPI stack (fixed by azbus_xml5.x on quick-xml 0.41).0.30.0— a build dep ofxcb 1.7.0(X11 protocol XML; trusted input, no runtime surface, and no released xcb uses quick-xml>=0.41).The advisories have no lower bound, so both match; cargo-deny just collapses the report to the
0.39.4node. So the earlier "drop the two ignores once zbus_xml ships" was over-optimistic — aftercargo update -p zbus_xmlthe xcb0.30.0build-dep still fires. The note now says to narrow (not delete) the entries to the xcb residual.Comment-only;
cargo deny check advisories→advisories ok.