Skip to content

Fix Dependabot: bytes (rust) - #2

Open
akoszowski wants to merge 1 commit into
mainfrom
cursor/fix-dependabot-bytes-71c7
Open

Fix Dependabot: bytes (rust)#2
akoszowski wants to merge 1 commit into
mainfrom
cursor/fix-dependabot-bytes-71c7

Conversation

@akoszowski

Copy link
Copy Markdown

Summary

Addresses RUSTSEC-2026-0007 (bytes 1.9.0 → 1.11.1, patched floor ≥1.11.1).

Dependency chain

Transitive via reqwest, hyper, tokio, risc0-zkvm, and quinn-proto (through the bonsai-sdk / risc0-zkvm stack).

Fix

  • cargo update -p bytes --precise 1.11.1 in Cargo.lock only.

Notes

  • Merge #1 (ring) first if lockfile conflicts appear.
  • Merge lockfile PRs one at a time.
Open in Web Open in Cursor 

Bump bytes from 1.9.0 to 1.11.1 (>=1.11.1) to address RUSTSEC-2026-0007.

Transitive via reqwest, hyper, tokio, risc0-zkvm, and quinn-proto.

Co-authored-by: Antoni Koszowski <akoszowski@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review July 28, 2026 12:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants