mirror of
https://github.com/openai/codex.git
synced 2026-08-23 13:09:46 +00:00
## Why The `cargo-deny` job on `main` began failing after [RUSTSEC-2026-0194](https://rustsec.org/advisories/RUSTSEC-2026-0194) and [RUSTSEC-2026-0195](https://rustsec.org/advisories/RUSTSEC-2026-0195) flagged the workspace `quick-xml 0.38.4`. Both denial-of-service issues are fixed in `quick-xml 0.41.0`. A `quick-xml 0.39.4` copy must temporarily remain because the latest `plist` and `wayland-scanner` releases have not adopted 0.41 yet. Neither retained path accepts attacker-controlled XML at runtime: `plist` does not exercise the affected APIs, and `wayland-scanner` parses trusted protocol definitions at build time. Compatible upstream bumps are already open in [rust-plist#191](https://github.com/ebarnard/rust-plist/pull/191) and [wayland-rs#938](https://github.com/Smithay/wayland-rs/pull/938). ## What changed - Upgrade the workspace `quick-xml` dependency used by `codex-protocol` to 0.41.0. - Refresh `Cargo.lock` and `MODULE.bazel.lock`; this also updates `plist` to 1.9.0 and `wayland-scanner` to 0.31.10. - Add synchronized, temporary `cargo-deny` and `cargo-audit` exceptions for the trusted `quick-xml 0.39.4` paths, with both upstream releases recorded as the removal condition. ## Testing - `cargo deny check` - `just test -p codex-protocol` (238 tests) - `just bazel-lock-check`