From 43c2c4017085291caf137b19b945ba7428cfc1f3 Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Tue, 29 Sep 2026 21:49:04 +1000 Subject: [PATCH 1/2] chore(core): drop unused bytes and byteorder dependencies (LAB-6345) Neither crate is referenced anywhere in the crate. Remove them from the manifest and lockfile, along with the cargo-vet exemption and import that only they used. --- Cargo.lock | 14 -------------- Cargo.toml | 4 ---- supply-chain/config.toml | 4 ---- supply-chain/imports.lock | 13 ++++++------- 4 files changed, 6 insertions(+), 29 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index df94f3a..4241d31 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -161,18 +161,6 @@ version = "3.20.2" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "5d20789868f4b01b2f2caec9f5c4e0213b41e3e5702a50157d699ae31ced2fcb" -[[package]] -name = "byteorder" -version = "1.5.0" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1fd0f2584146f6f2ef48085050886acf353beff7305ebd1ae69500e27c67f64b" - -[[package]] -name = "bytes" -version = "1.11.1" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1e748733b7cbc798e1434b6ac524f0c1ff2ab456fe201501e6497c8417a4fc33" - [[package]] name = "cachekit-core" version = "0.6.0" @@ -180,8 +168,6 @@ dependencies = [ "aes", "aes-gcm", "blake2", - "byteorder", - "bytes", "cbindgen", "criterion", "generic-array", diff --git a/Cargo.toml b/Cargo.toml index 1362ba8..4d898ad 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -52,10 +52,6 @@ getrandom = { version = "0.2", features = ["js"], optional = true } aes-gcm = { version = "0.10", features = ["zeroize"], optional = true } aes = { version = "0.8", features = ["zeroize"], optional = true } -# Byte utilities -bytes = "1.5" -byteorder = "1.5" - [target.'cfg(not(target_arch = "wasm32"))'.dependencies] # ring: hardware-accelerated AES-256-GCM for native targets only. # Does NOT compile on wasm32-unknown-unknown (requires clang for C asm). diff --git a/supply-chain/config.toml b/supply-chain/config.toml index 8ae2abb..e2d4c4a 100644 --- a/supply-chain/config.toml +++ b/supply-chain/config.toml @@ -65,10 +65,6 @@ criteria = "safe-to-deploy" version = "0.10.6" criteria = "safe-to-run" -[[exemptions.bytes]] -version = "1.11.1" -criteria = "safe-to-deploy" - [[exemptions.cbindgen]] version = "0.29.2" criteria = "safe-to-deploy" diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock index a957518..986b1ed 100644 --- a/supply-chain/imports.lock +++ b/supply-chain/imports.lock @@ -341,6 +341,12 @@ criteria = "safe-to-deploy" delta = "0.9.15 -> 0.9.18" notes = "Nontrivial update but mostly around dependencies and how `unsafe` code is managed. Everything looks the same shape as before." +[[audits.bytecode-alliance.audits.crossbeam-epoch]] +who = "Alex Crichton " +criteria = "safe-to-deploy" +delta = "0.9.18 -> 0.9.20" +notes = "Minor updates, nothing out of place." + [[audits.bytecode-alliance.audits.errno]] who = "Dan Gohman " criteria = "safe-to-deploy" @@ -505,13 +511,6 @@ Additional review comments can be found at https://crrev.com/c/4723145/31 """ aggregated-from = "https://chromium.googlesource.com/chromium/src/+/main/third_party/rust/chromium_crates_io/supply-chain/audits.toml?format=TEXT" -[[audits.google.audits.byteorder]] -who = "danakj " -criteria = "safe-to-deploy" -version = "1.5.0" -notes = "Unsafe review in https://crrev.com/c/5838022" -aggregated-from = "https://chromium.googlesource.com/chromium/src/+/main/third_party/rust/chromium_crates_io/supply-chain/audits.toml?format=TEXT" - [[audits.google.audits.cast]] who = "George Burgess IV " criteria = "safe-to-run" From 10b432fca163b03f1c789b93101f29663aa7b310 Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Tue, 29 Sep 2026 23:01:45 +1000 Subject: [PATCH 2/2] chore(core): keep supply-chain changes to the removed crates only Revert an unrelated crossbeam-epoch import that cargo vet added while regenerating imports.lock. --- supply-chain/imports.lock | 6 ------ 1 file changed, 6 deletions(-) diff --git a/supply-chain/imports.lock b/supply-chain/imports.lock index 986b1ed..50ca26f 100644 --- a/supply-chain/imports.lock +++ b/supply-chain/imports.lock @@ -341,12 +341,6 @@ criteria = "safe-to-deploy" delta = "0.9.15 -> 0.9.18" notes = "Nontrivial update but mostly around dependencies and how `unsafe` code is managed. Everything looks the same shape as before." -[[audits.bytecode-alliance.audits.crossbeam-epoch]] -who = "Alex Crichton " -criteria = "safe-to-deploy" -delta = "0.9.18 -> 0.9.20" -notes = "Minor updates, nothing out of place." - [[audits.bytecode-alliance.audits.errno]] who = "Dan Gohman " criteria = "safe-to-deploy"