From 308be51d08a200e7cddb1ef8622c9eab3f12da2c Mon Sep 17 00:00:00 2001 From: Tristen Wen Date: Fri, 18 Jul 2025 15:04:17 +0800 Subject: [PATCH] feat: update pre-commit hooks and fix security vulnerabilities - Update pre-commit-hooks v2.3.0 -> v5.0.0 - Update black 19.3b0 -> 25.1.0 - Update typos v1.8.1 -> v1.34.0 - Fix security issues in ring and tokio dependencies - Modernize deny.toml configuration - Fix clippy warnings with modern string formatting - Update test fixtures to handle variable HTTP headers --- .pre-commit-config.yaml | 8 +-- Cargo.lock | 36 +++++++----- cli-utils/src/lib.rs | 4 +- deny.toml | 113 ++++++++++-------------------------- requester/fixtures/diff.yml | 2 + requester/src/diff.rs | 8 +-- requester/src/req.rs | 2 +- xdiff/src/main.rs | 2 +- xreq/src/main.rs | 6 +- 9 files changed, 69 insertions(+), 112 deletions(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 627201a..2bdf00e 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,7 +1,7 @@ fail_fast: false repos: - repo: https://github.com/pre-commit/pre-commit-hooks - rev: v2.3.0 + rev: v5.0.0 hooks: - id: check-byte-order-marker - id: check-case-conflict @@ -12,11 +12,11 @@ repos: - id: mixed-line-ending - id: trailing-whitespace - repo: https://github.com/psf/black - rev: 19.3b0 + rev: 25.1.0 hooks: - id: black - repo: https://github.com/crate-ci/typos - rev: v1.8.1 + rev: v1.34.0 hooks: - id: typos - repo: local @@ -52,7 +52,7 @@ repos: - id: cargo-test name: cargo test description: unit test for the project - entry: bash -c 'cargo nextest run --all-features' + entry: bash -c 'cargo test --all-features' language: rust files: \.rs$ pass_filenames: false diff --git a/Cargo.lock b/Cargo.lock index 566f0fe..44ea4d1 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -225,9 +225,9 @@ checksum = "325918d6fe32f23b19878fe4b34794ae41fc19ddbe53b10571a4874d44ffd39b" [[package]] name = "cc" -version = "1.2.4" +version = "1.2.29" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9157bbaa6b165880c27a4293a474c91cdcf265cc68cc829bf10be0964a391caf" +checksum = "5c1599538de2394445747c8cf7935946e3cc27e9625f889d979bfb2aaf569362" dependencies = [ "shlex", ] @@ -850,6 +850,17 @@ dependencies = [ "serde", ] +[[package]] +name = "io-uring" +version = "0.7.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b86e202f00093dcba4275d4636b93ef9dd75d025ae560d2521b45ea28ab49013" +dependencies = [ + "bitflags 2.6.0", + "cfg-if", + "libc", +] + [[package]] name = "ipnet" version = "2.10.1" @@ -1252,15 +1263,14 @@ dependencies = [ [[package]] name = "ring" -version = "0.17.8" +version = "0.17.14" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c17fa4cb658e3583423e915b9f3acc01cceaee1860e33d59ebae66adc3a2dc0d" +checksum = "a4689e6c2294d81e88dc6261c768b63bc4fcdb852be6d1352498b114f61383b7" dependencies = [ "cc", "cfg-if", "getrandom", "libc", - "spin", "untrusted", "windows-sys 0.52.0", ] @@ -1507,12 +1517,6 @@ dependencies = [ "windows-sys 0.52.0", ] -[[package]] -name = "spin" -version = "0.9.8" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "6980e8d7511241f8acf4aebddbb1ff938df5eebe98691418c4468d0b72a96a67" - [[package]] name = "stable_deref_trait" version = "1.2.0" @@ -1695,17 +1699,19 @@ checksum = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20" [[package]] name = "tokio" -version = "1.42.0" +version = "1.46.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5cec9b21b0450273377fc97bd4c33a8acffc8c996c987a7c5b319a0083707551" +checksum = "0cc3a2344dafbe23a245241fe8b09735b521110d30fcefbbd5feb1797ca35d17" dependencies = [ "backtrace", "bytes", + "io-uring", "libc", "mio", "parking_lot", "pin-project-lite", "signal-hook-registry", + "slab", "socket2", "tokio-macros", "windows-sys 0.52.0", @@ -1713,9 +1719,9 @@ dependencies = [ [[package]] name = "tokio-macros" -version = "2.4.0" +version = "2.5.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "693d596312e88961bc67d7f1f97af8a70227d9f90c31bba5806eec004978d752" +checksum = "6e06d43f1345a3bcd39f6a56dbb7dcab2ba47e68e8ac134855e7e2bdbaf8cab8" dependencies = [ "proc-macro2", "quote", diff --git a/cli-utils/src/lib.rs b/cli-utils/src/lib.rs index c22ce17..f75c2f2 100644 --- a/cli-utils/src/lib.rs +++ b/cli-utils/src/lib.rs @@ -44,8 +44,8 @@ pub fn get_config_file(s: &str) -> Result { pub fn get_default_config(name: &str) -> Result { let paths = [ format!("{}/.config/{}", std::env::var("HOME").unwrap(), name), - format!("./{}", name), - format!("/etc/{}", name), + format!("./{name}"), + format!("/etc/{name}"), ]; for path in paths.iter() { diff --git a/deny.toml b/deny.toml index 8ff1eb9..8a25f3a 100644 --- a/deny.toml +++ b/deny.toml @@ -9,6 +9,11 @@ # The values provided in this template are the default values that will be used # when any section or field is not specified in your own configuration +# Root options + +# The graph table configures how the dependency graph is constructed and thus +# which crates the checks are performed against +[graph] # If 1 or more target triples (and optionally, target_features) are specified, # only the specified targets will be checked when running `cargo deny check`. # This means, if a particular package is only ever used as a target specific @@ -20,7 +25,7 @@ targets = [ # The triple can be any string, but only the target triples built in to # rustc (as of 1.40) can be checked against actual config expressions - #{ triple = "x86_64-unknown-linux-musl" }, + #"x86_64-unknown-linux-musl", # You can also specify which target_features you promise are enabled for a # particular target. target_features are currently not validated against # the actual valid features supported by the target architecture. @@ -31,44 +36,25 @@ targets = [ # More documentation for the advisories section can be found here: # https://embarkstudios.github.io/cargo-deny/checks/advisories/cfg.html [advisories] -# The path where the advisory database is cloned/fetched into -db-path = "~/.cargo/advisory-db" +# The path where the advisory databases are cloned/fetched into +#db-path = "$CARGO_HOME/advisory-dbs" # The url(s) of the advisory databases to use -db-urls = ["https://github.com/rustsec/advisory-db"] -# The lint level for security vulnerabilities -vulnerability = "deny" -# The lint level for unmaintained crates -unmaintained = "warn" -# The lint level for crates that have been yanked from their source registry -yanked = "warn" -# The lint level for crates with security notices. Note that as of -# 2019-12-17 there are no security notice advisories in -# https://github.com/rustsec/advisory-db -notice = "warn" +#db-urls = ["https://github.com/rustsec/advisory-db"] # A list of advisory IDs to ignore. Note that ignored advisories will still # output a note when they are encountered. ignore = [ - #"RUSTSEC-0000-0000", + { id = "RUSTSEC-2024-0375", reason = "atty unmaintained - using for terminal output only, no security impact" }, + { id = "RUSTSEC-2021-0145", reason = "atty unsound - using for terminal output only, no security impact" }, + { id = "RUSTSEC-2024-0320", reason = "yaml-rust unmaintained - used by syntect for syntax highlighting, no user input parsing" }, ] -# Threshold for security vulnerabilities, any vulnerability with a CVSS score -# lower than the range specified will be ignored. Note that ignored advisories -# will still output a note when they are encountered. -# * None - CVSS Score 0.0 -# * Low - CVSS Score 0.1 - 3.9 -# * Medium - CVSS Score 4.0 - 6.9 -# * High - CVSS Score 7.0 - 8.9 -# * Critical - CVSS Score 9.0 - 10.0 -#severity-threshold = # This section is considered when running `cargo deny check licenses` # More documentation for the licenses section can be found here: # https://embarkstudios.github.io/cargo-deny/checks/licenses/cfg.html [licenses] -# The lint level for crates which do not have a detectable license -unlicensed = "allow" # List of explicitly allowed licenses # See https://spdx.org/licenses/ for list of possible licenses -# [possible values: any SPDX 3.7 short identifier (+ optional exception)]. +# [possible values: any SPDX 3.11 short identifier (+ optional exception)]. allow = [ "MIT", "Apache-2.0", @@ -76,29 +62,8 @@ allow = [ "BSD-3-Clause", "MPL-2.0", "ISC", - "Unicode-DFS-2016", "Unicode-3.0", ] -# List of explicitly disallowed licenses -# See https://spdx.org/licenses/ for list of possible licenses -# [possible values: any SPDX 3.7 short identifier (+ optional exception)]. -deny = [ - #"Nokia", -] -# Lint level for licenses considered copyleft -copyleft = "warn" -# Blanket approval or denial for OSI-approved or FSF Free/Libre licenses -# * both - The license will be approved if it is both OSI-approved *AND* FSF -# * either - The license will be approved if it is either OSI-approved *OR* FSF -# * osi-only - The license will be approved if is OSI-approved *AND NOT* FSF -# * fsf-only - The license will be approved if is FSF *AND NOT* OSI-approved -# * neither - This predicate is ignored and the default lint level is used -allow-osi-fsf-free = "neither" -# Lint level used when no other predicates are matched -# 1. License isn't in the allow or deny lists -# 2. License isn't copyleft -# 3. License isn't OSI/FSF, or allow-osi-fsf-free = "neither" -default = "deny" # The confidence threshold for detecting a license from license text. # The higher the value, the more closely the license text must be to the # canonical license text of a valid SPDX license file. @@ -109,32 +74,14 @@ confidence-threshold = 0.8 exceptions = [ # Each entry is the crate and version constraint, and its specific allow # list - #{ allow = ["Zlib"], name = "adler32", version = "*" }, + #{ allow = ["Zlib"], crate = "adler32" }, ] -# Some crates don't have (easily) machine readable licensing information, -# adding a clarification entry for it allows you to manually specify the -# licensing information -#[[licenses.clarify]] -# The name of the crate the clarification applies to -#name = "ring" -# The optional version constraint for the crate -#version = "*" -# The SPDX expression for the license requirements of the crate -#expression = "MIT AND ISC AND OpenSSL" -# One or more files in the crate's source used as the "source of truth" for -# the license expression. If the contents match, the clarification will be used -# when running the license check, otherwise the clarification will be ignored -# and the crate will be checked normally, which may produce warnings or errors -# depending on the rest of your configuration -#license-files = [ -# Each entry is a crate relative path, and the (opaque) hash of its contents -#{ path = "LICENSE", hash = 0xbd0eed23 } -#] - [licenses.private] # If true, ignores workspace crates that aren't published, or are only -# published to private registries +# published to private registries. +# To see how to mark a crate as unpublished (to the official registry), +# visit https://doc.rust-lang.org/cargo/reference/manifest.html#the-publish-field. ignore = false # One or more private registries that you might publish crates to, if a crate # is only published to private registries, and ignore is true, the crate will @@ -159,28 +106,30 @@ wildcards = "allow" highlight = "all" # List of crates that are allowed. Use with care! allow = [ - #{ name = "ansi_term", version = "=0.11.0" }, + #"ansi_term@0.11.0", + #{ crate = "ansi_term@0.11.0", reason = "you can specify a reason it is allowed" }, ] # List of crates to deny deny = [ - # Each entry the name of a crate and a version range. If version is - # not specified, all versions will be matched. - #{ name = "ansi_term", version = "=0.11.0" }, - # + #"ansi_term@0.11.0", + #{ crate = "ansi_term@0.11.0", reason = "you can specify a reason it is banned" }, # Wrapper crates can optionally be specified to allow the crate when it # is a direct dependency of the otherwise banned crate - #{ name = "ansi_term", version = "=0.11.0", wrappers = [] }, + #{ crate = "ansi_term@0.11.0", wrappers = ["this-crate-directly-depends-on-ansi_term"] }, ] + # Certain crates/versions that will be skipped when doing duplicate detection. skip = [ - #{ name = "ansi_term", version = "=0.11.0" }, + #"ansi_term@0.11.0", + #{ crate = "ansi_term@0.11.0", reason = "you can specify a reason why it can't be updated/removed" }, ] # Similarly to `skip` allows you to skip certain crates during duplicate # detection. Unlike skip, it also includes the entire tree of transitive # dependencies starting at the specified crate, up to a certain depth, which is -# by default infinite +# by default infinite. skip-tree = [ - #{ name = "ansi_term", version = "=0.11.0", depth = 20 }, + #"ansi_term@0.11.0", # will be skipped along with _all_ of its direct and transitive dependencies + #{ crate = "ansi_term@0.11.0", depth = 20 }, ] # This section is considered when running `cargo deny check sources`. @@ -200,9 +149,9 @@ allow-registry = ["https://github.com/rust-lang/crates.io-index"] allow-git = [] [sources.allow-org] -# 1 or more github.com organizations to allow git sources for +# github.com organizations to allow git sources for github = [] -# 1 or more gitlab.com organizations to allow git sources for +# gitlab.com organizations to allow git sources for gitlab = [] -# 1 or more bitbucket.org organizations to allow git sources for +# bitbucket.org organizations to allow git sources for bitbucket = [] diff --git a/requester/fixtures/diff.yml b/requester/fixtures/diff.yml index ffa33c1..eb3091f 100644 --- a/requester/fixtures/diff.yml +++ b/requester/fixtures/diff.yml @@ -16,6 +16,8 @@ rust: - date - via - x-amz-cf-id + - report-to + - reporting-endpoints todo: request1: url: https://jsonplaceholder.typicode.com/todos/1 diff --git a/requester/src/diff.rs b/requester/src/diff.rs index e610ae0..dcf1df7 100644 --- a/requester/src/diff.rs +++ b/requester/src/diff.rs @@ -123,7 +123,7 @@ impl DiffContext { let text2 = self.request_to_string(res2).await?; if text1 != text2 { - let headers = format!("--- a/{}\n+++ b/{}\n", url1, url2); + let headers = format!("--- a/{url1}\n+++ b/{url2}\n"); return Ok(DiffResult::Diff(build_diff(headers, text1, text2)?)); } @@ -138,7 +138,7 @@ impl DiffContext { if self.response.skip_headers.iter().any(|v| v == k.as_str()) { return; } - writeln!(&mut buf, "{}: {:?}", k, v).unwrap(); + writeln!(&mut buf, "{k}: {v:?}").unwrap(); }); writeln!(&mut buf).unwrap(); @@ -148,7 +148,7 @@ impl DiffContext { body = serde_json::to_string_pretty(&json)?; } - writeln!(&mut buf, "{}", body).unwrap(); + writeln!(&mut buf, "{body}").unwrap(); Ok(String::from_utf8(buf)?) } @@ -157,7 +157,7 @@ impl DiffContext { fn build_diff(headers: String, old: String, new: String) -> Result { let diff = TextDiff::from_lines(&old, &new); let mut buf = Vec::with_capacity(4096); - writeln!(&mut buf, "{}", headers).unwrap(); + writeln!(&mut buf, "{headers}").unwrap(); for (idx, group) in diff.grouped_ops(3).iter().enumerate() { if idx > 0 { writeln!(&mut buf, "{:-^1$}", "-", 80)?; diff --git a/requester/src/req.rs b/requester/src/req.rs index 7c19b71..3cf37ab 100644 --- a/requester/src/req.rs +++ b/requester/src/req.rs @@ -175,7 +175,7 @@ impl FromStr for RequestContext { } else if val.is_array() { val.as_array_mut().unwrap().push(v); } else { - panic!("unexpected value: {:?}", val); + panic!("unexpected value: {val:?}"); } } None => { diff --git a/xdiff/src/main.rs b/xdiff/src/main.rs index 376e2cf..835f266 100644 --- a/xdiff/src/main.rs +++ b/xdiff/src/main.rs @@ -50,7 +50,7 @@ async fn main() -> Result<()> { let stdout = std::io::stdout(); let mut stdout = stdout.lock(); for line in output { - write!(stdout, "{}", line)?; + write!(stdout, "{line}")?; } Ok(()) diff --git a/xreq/src/main.rs b/xreq/src/main.rs index bb41192..b4acaf3 100644 --- a/xreq/src/main.rs +++ b/xreq/src/main.rs @@ -67,7 +67,7 @@ async fn main() -> Result<()> { let stdout = std::io::stdout(); let mut stdout = stdout.lock(); for line in output { - write!(stdout, "{}", line)?; + write!(stdout, "{line}")?; } Ok(()) @@ -125,7 +125,7 @@ async fn run(output: &mut Vec, args: RunArgs) -> Result<()> { fn print_status(output: &mut Vec, resp: &Response) { let status = format!("{:?} {}", resp.version(), resp.status()).blue(); - output.push(format!("{}\n", status)); + output.push(format!("{status}\n")); } fn print_headers(output: &mut Vec, resp: &Response) { @@ -146,7 +146,7 @@ fn print_body(output: &mut Vec, m: Option, body: String) -> Result Some(v) if v == mime::TEXT_HTML => print_syntect(output, body, "html"), _ => { - output.push(format!("{}\n", body)); + output.push(format!("{body}\n")); Ok(()) } }