deps(python): upgrade pyo3 + rust-numpy to 0.29, clear 2 advisories (#295)
rust-numpy 0.29 lifted its pyo3 ^0.28 pin, so the resolver can now select pyo3 0.29. Bump both (kept as a pair) and drop the temporary not-affected exceptions for RUSTSEC-2026-0176 and RUSTSEC-2026-0177 from deny.toml and osv-scanner.toml — pyo3 0.29 fixes both advisories. No public API change; the Python test suite passes unchanged (957 tests).
This commit is contained in:
@@ -15,6 +15,16 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
the language label, lists C and C++ separately, prefers `Node.js` and `WASM` in
|
the language label, lists C and C++ separately, prefers `Node.js` and `WASM` in
|
||||||
prose, and frames the C ABI as a hub (`C ABI hub → …`) rather than a
|
prose, and frames the C ABI as a hub (`C ABI hub → …`) rather than a
|
||||||
language-list entry. Documentation only — no code or public API changes.
|
language-list entry. Documentation only — no code or public API changes.
|
||||||
|
- Python binding: upgraded `pyo3` and `rust-numpy` from 0.28 to 0.29. No public
|
||||||
|
API changes; the full test suite passes unchanged.
|
||||||
|
|
||||||
|
### Security
|
||||||
|
- Resolved the pyo3 advisories RUSTSEC-2026-0176 (out-of-bounds read in
|
||||||
|
`PyList`/`PyTuple` `nth`/`nth_back`) and RUSTSEC-2026-0177 (missing `Sync`
|
||||||
|
bound on `PyCFunction::new_closure`) by upgrading to pyo3 0.29, which fixes
|
||||||
|
both. The upgrade was previously blocked upstream by rust-numpy 0.28 pinning
|
||||||
|
pyo3 `^0.28`; rust-numpy 0.29 lifts that pin. The not-affected exceptions are
|
||||||
|
removed from `deny.toml` and `osv-scanner.toml`.
|
||||||
|
|
||||||
## [0.9.0] - 2026-06-13
|
## [0.9.0] - 2026-06-13
|
||||||
|
|
||||||
|
|||||||
Generated
+12
-13
@@ -945,9 +945,9 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "numpy"
|
name = "numpy"
|
||||||
version = "0.28.0"
|
version = "0.29.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "778da78c64ddc928ebf5ad9df5edf0789410ff3bdbf3619aed51cd789a6af1e2"
|
checksum = "6a5b15d63a5ff39e378daed0e1340d3a5964703ea9712eb09a0dc66fade996f4"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"libc",
|
"libc",
|
||||||
"ndarray",
|
"ndarray",
|
||||||
@@ -1152,9 +1152,9 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "pyo3"
|
name = "pyo3"
|
||||||
version = "0.28.3"
|
version = "0.29.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "91fd8e38a3b50ed1167fb981cd6fd60147e091784c427b8f7183a7ee32c31c12"
|
checksum = "cd274650b21d4bfc26a0a47587962c1edb425f69287324355cd040c3ea66071c"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"libc",
|
"libc",
|
||||||
"once_cell",
|
"once_cell",
|
||||||
@@ -1166,18 +1166,18 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "pyo3-build-config"
|
name = "pyo3-build-config"
|
||||||
version = "0.28.3"
|
version = "0.29.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "e368e7ddfdeb98c9bca7f8383be1648fd84ab466bf2bc015e94008db6d35611e"
|
checksum = "c5e2a7d2f0d013342f295c048ad19237add5154a55b1c5a254c0ec93d4109078"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"target-lexicon",
|
"target-lexicon",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "pyo3-ffi"
|
name = "pyo3-ffi"
|
||||||
version = "0.28.3"
|
version = "0.29.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "7f29e10af80b1f7ccaf7f69eace800a03ecd13e883acfacc1e5d0988605f651e"
|
checksum = "ca85c467da1bbc8d866eea5deff9cf29ea5f7785054a17da36e65bda9c05845b"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"libc",
|
"libc",
|
||||||
"pyo3-build-config",
|
"pyo3-build-config",
|
||||||
@@ -1185,9 +1185,9 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "pyo3-macros"
|
name = "pyo3-macros"
|
||||||
version = "0.28.3"
|
version = "0.29.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "df6e520eff47c45997d2fc7dd8214b25dd1310918bbb2642156ef66a67f29813"
|
checksum = "9ac53762fd065daa3194dd09337a38bd793a188100fd1a9304c4ab312d901771"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"proc-macro2",
|
"proc-macro2",
|
||||||
"pyo3-macros-backend",
|
"pyo3-macros-backend",
|
||||||
@@ -1197,13 +1197,12 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "pyo3-macros-backend"
|
name = "pyo3-macros-backend"
|
||||||
version = "0.28.3"
|
version = "0.29.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "c4cdc218d835738f81c2338f822078af45b4afdf8b2e33cbb5916f108b813acb"
|
checksum = "4ca3a1557399783172dc5bf39cfca835157732532cba56b71d2292161e53b362"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"heck",
|
"heck",
|
||||||
"proc-macro2",
|
"proc-macro2",
|
||||||
"pyo3-build-config",
|
|
||||||
"quote",
|
"quote",
|
||||||
"syn",
|
"syn",
|
||||||
]
|
]
|
||||||
|
|||||||
+2
-2
@@ -37,8 +37,8 @@ approx = "0.5"
|
|||||||
criterion = { version = "0.8", features = ["html_reports"] }
|
criterion = { version = "0.8", features = ["html_reports"] }
|
||||||
|
|
||||||
# Python binding
|
# Python binding
|
||||||
pyo3 = { version = "0.28", features = ["extension-module", "abi3-py39"] }
|
pyo3 = { version = "0.29", features = ["extension-module", "abi3-py39"] }
|
||||||
numpy = "0.28"
|
numpy = "0.29"
|
||||||
|
|
||||||
[workspace.lints.rust]
|
[workspace.lints.rust]
|
||||||
unsafe_code = "forbid"
|
unsafe_code = "forbid"
|
||||||
|
|||||||
@@ -9,18 +9,6 @@ all-features = true
|
|||||||
# Fail on any security advisory or unmaintained/unsound crate in the tree.
|
# Fail on any security advisory or unmaintained/unsound crate in the tree.
|
||||||
version = 2
|
version = 2
|
||||||
yanked = "deny"
|
yanked = "deny"
|
||||||
# Temporary, upstream-blocked exception. Both advisories are fixed in pyo3
|
|
||||||
# 0.29.0, but rust-numpy 0.28 (latest release) hard-pins `pyo3 ^0.28.0`, so the
|
|
||||||
# resolver cannot select 0.29 until rust-numpy ships a 0.29-compatible release
|
|
||||||
# (PyO3/rust-numpy "Updated to PyO3 version 0.29.0" is open, not yet published).
|
|
||||||
# Neither vulnerable code path is reachable from our binding: it never calls
|
|
||||||
# `BoundListIterator::nth`/`nth_back` or the `PyTuple` equivalents (0176), nor
|
|
||||||
# `PyCFunction::new_closure` (0177) — verified by grep over bindings/python/src.
|
|
||||||
# Remove both once rust-numpy 0.29 lands and the pyo3 0.29 bump goes in.
|
|
||||||
ignore = [
|
|
||||||
"RUSTSEC-2026-0176",
|
|
||||||
"RUSTSEC-2026-0177",
|
|
||||||
]
|
|
||||||
|
|
||||||
[bans]
|
[bans]
|
||||||
# Catch accidental duplicate versions and wildcard ("*") version requirements.
|
# Catch accidental duplicate versions and wildcard ("*") version requirements.
|
||||||
|
|||||||
@@ -4,28 +4,6 @@
|
|||||||
# `ignore` list in deny.toml at the OSV layer. See the "Vulnerability
|
# `ignore` list in deny.toml at the OSV layer. See the "Vulnerability
|
||||||
# exploitability (VEX)" section of SECURITY.md.
|
# exploitability (VEX)" section of SECURITY.md.
|
||||||
|
|
||||||
# pyo3 — both advisories are fixed in pyo3 0.29.0, but rust-numpy 0.28 (latest
|
|
||||||
# release) hard-pins pyo3 ^0.28.0, so the bump is upstream-blocked. Neither
|
|
||||||
# vulnerable code path is reachable from the binding: it never calls
|
|
||||||
# BoundListIterator nth/nth_back, the PyTuple equivalents, or
|
|
||||||
# PyCFunction::new_closure (verified by grep over bindings/python/src). Also
|
|
||||||
# tracked in deny.toml; remove once rust-numpy 0.29 ships and pyo3 is bumped.
|
|
||||||
[[IgnoredVulns]]
|
|
||||||
id = "RUSTSEC-2026-0176"
|
|
||||||
reason = "pyo3 OOB read in PyList/PyTuple nth/nth_back; vulnerable API unused; fix blocked upstream by rust-numpy. Tracked in deny.toml."
|
|
||||||
|
|
||||||
[[IgnoredVulns]]
|
|
||||||
id = "GHSA-36hh-v3qg-5jq4"
|
|
||||||
reason = "Alias of RUSTSEC-2026-0176."
|
|
||||||
|
|
||||||
[[IgnoredVulns]]
|
|
||||||
id = "RUSTSEC-2026-0177"
|
|
||||||
reason = "pyo3 missing Sync on PyCFunction::new_closure; vulnerable API unused; fix blocked upstream by rust-numpy. Tracked in deny.toml."
|
|
||||||
|
|
||||||
[[IgnoredVulns]]
|
|
||||||
id = "GHSA-chgr-c6px-7xpp"
|
|
||||||
reason = "Alias of RUSTSEC-2026-0177."
|
|
||||||
|
|
||||||
# jackson-core 3.x async-parser DoS — tools.jackson.core:jackson-core 3.x is not
|
# jackson-core 3.x async-parser DoS — tools.jackson.core:jackson-core 3.x is not
|
||||||
# a dependency of this project. No manifest, Maven plugin, or the GitHub
|
# a dependency of this project. No manifest, Maven plugin, or the GitHub
|
||||||
# dependency-graph SBOM references jackson 3.x; the only jackson present is
|
# dependency-graph SBOM references jackson 3.x; the only jackson present is
|
||||||
|
|||||||
Reference in New Issue
Block a user