Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ jobs:
# Uploading the artifact needs no Pages configuration, so this stays
# unconditional: the built site is downloadable from the run even while
# publishing is off, which is how the owner can eyeball it before deciding.
- uses: actions/upload-pages-artifact@v4
- uses: actions/upload-pages-artifact@v5
with:
path: apps/docs/dist

Expand All @@ -95,4 +95,4 @@ jobs:
url: ${{ steps.deployment.outputs.page_url }}
steps:
- id: deployment
uses: actions/deploy-pages@v4
uses: actions/deploy-pages@v5
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@ storybook-static/

# Vitest browser-mode failure screenshots
**/__screenshots__/
# Vitest 4 writes failure screenshots/traces here as well, keyed by content hash.
**/.vitest-attachments/

# Rust / Tauri build output + generated files
target/
Expand Down
38 changes: 14 additions & 24 deletions apps/desktop/src-tauri/.cargo/audit.toml
Original file line number Diff line number Diff line change
Expand Up @@ -6,31 +6,21 @@
# advisory on a direct dependency we can bump ourselves.

[advisories]
ignore = [
# quick-xml <0.41 DoS advisories (RUSTSEC-2026-0194 quadratic duplicate-
# attribute check, RUSTSEC-2026-0195 unbounded NsReader namespace
# allocation), published 2026-06-29. Pulled twice, both upstream-pinned:
# - 0.39.4 via plist → tauri (macOS Info.plist parsing)
# - 0.37.5 via tauri-winrt-notification → notify-rust →
# tauri-plugin-notification (Windows toast XML)
# No tauri/plist/notify-rust release with quick-xml >=0.41 exists yet, and
# the parsers only see Nightcore's own bundled plists / OS notification
# XML, not attacker-supplied documents. Re-check after each tauri bump
# (`cargo audit` from this dir) and remove once these resolve.
"RUSTSEC-2026-0194",
"RUSTSEC-2026-0195",
]
# Empty: `cargo update` collapsed both locked quick-xml instances (0.39.4 via
# plist → tauri, 0.37.5 via tauri-winrt-notification → notify-rust →
# tauri-plugin-notification) into a single quick-xml 0.41.x, clearing
# RUSTSEC-2026-0194 and RUSTSEC-2026-0195. See git history for the prior
# ignore entries.
ignore = []

# Informational advisories deliberately NOT ignored (reviewed 2026-09-21, re-check
# by 2026-10-21). `cargo audit` reports them as warnings and does not fail on
# them; they stay visible here instead of being silenced. All are upstream-pinned
# by tauri 2 with no release that drops them:
# Informational advisories deliberately NOT ignored (reviewed 2026-10-01).
# `cargo audit` reports them as warnings and does not fail on them; they stay
# visible here instead of being silenced. Both are upstream-pinned by tauri 2
# with no release that drops them:
# - unmaintained proc-macro-error (RUSTSEC-2024-0370) + unsound glib 0.18
# VariantStrIter (RUSTSEC-2024-0429): gtk-rs 0.18 via muda/wry/tauri —
# VariantStrIter (RUSTSEC-2024-0429): gtk-rs 0.18 via muda/wry/tauri,
# Linux (webkit2gtk) build only, absent from the macOS/Windows trees.
# Nightcore never iterates a GVariant string array itself.
# - unmaintained unic-* (RUSTSEC-2025-0075/0080/0081/0098/0100): urlpattern
# 0.3 via tauri-utils 2.9.3 (latest 2.x). Parses capability URL patterns
# from our own bundled tauri config, not untrusted input.
# RUSTSEC-2026-0285 (rustls), -0190 (anyhow) and -0221 (event-listener) were
# fixed by lockfile bumps (rustls 0.23.45, anyhow 1.0.104, event-listener 5.4.2).
# The unmaintained unic-* warnings (RUSTSEC-2025-0075/0080/0081/0098/0100) left
# with tauri-utils 2.10 (urlpattern 0.6). RUSTSEC-2026-0285 (rustls), -0190
# (anyhow) and -0221 (event-listener) were fixed by earlier lockfile bumps.
Loading
Loading