返回 CodeWhale
dependency-maintenance.md
根目录 / docs / dependency-maintenance.md
1 # Dependency maintenance
2
3 Reviewed against the 0.9.13 Core dependency graph on September 8, 2026.
4 This records maintenance decisions, not a security clearance or release test.
5
6 The terminal Markdown renderer uses Syntect's embedded syntax and theme dumps
7 with the existing fancy-regex backend. It does not load external syntax YAML,
8 theme plists, or emit Syntect HTML. Selecting those features explicitly removes
9 the unused `yaml-rust`, `plist`, and `quick-xml` dependency path. The embedded
10 YAML language grammar remains available for highlighting YAML code blocks.
11
12 `derivative`, `fxhash`, `paste`, and `ttf-parser` are absent from the Core lockfile.
13 Their obsolete advisory exceptions are removed so a future reintroduction is
14 visible to the advisory checks. No `cargo-audit` advisory is ignored.
15
16 The remaining `cargo-deny` maintenance exception is
17 [RUSTSEC-2025-0141](https://rustsec.org/advisories/RUSTSEC-2025-0141.html)
18 for `bincode` 1.3.3. Syntect 5.3.0 requires it to deserialize its compiled-in
19 syntax and theme assets and for its parser's internal lazy-context encoding.
20 Codewhale does not pass arbitrary external dump files to these loaders. The
21 maintenance warning remains visible in `cargo-audit`; the lack of an identified
22 exploit in this advisory does not guarantee safety.
23
24 Revisit the exception when upgrading or replacing Syntect, or before adding
25 external dump, grammar, or theme loading. Remove it when the dependency leaves
26 the graph. A replacement must preserve embedded language/theme coverage,
27 multiline highlighting and error recovery, and pass the existing Markdown
28 renderer tests with a resolver-verified lockfile. Adding ignores for new
29 advisories requires a separate assessment.
30
31 The Apps desktop lockfile and its platform dependencies are a separate graph;
32 this Core cleanup does not resolve their maintenance or GLib qualification work.
33
34 Automatic Git review and workspace polling require the runtime configuration
35 override interface introduced in [Git 2.31](https://github.com/git/git/blob/master/Documentation/RelNotes/2.31.0.adoc). The shared read authority probes the
36 resolved absolute executable once per process and pins subsequent commands to
37 that executable even if PATH changes. It refuses automatic reads if the executable
38 cannot honor those overrides; explicit user Git writes retain their existing behavior.
39 The porcelain-v1 display fallback does not waive this safety requirement.
40 The absolute path fixes executable search selection; it does not authenticate an
41 executable replaced at that path by the same local user.
42
43 Local fixtures cover native modern Git and an emulated executable that ignores
44 runtime overrides. They do not qualify a real older-Git installation, partial
45 clones, or all platform-specific Git behavior.
46
46 lines MARKDOWN