| 1 | # Dependency maintenance |
| 2 | |
| 3 | Reviewed against the 0.9.13 Core dependency graph on September 8, 2026. |
| 4 | This records maintenance decisions, not a security clearance or release test. |
| 5 | |
| 6 | The terminal Markdown renderer uses Syntect's embedded syntax and theme dumps |
| 7 | with the existing fancy-regex backend. It does not load external syntax YAML, |
| 8 | theme plists, or emit Syntect HTML. Selecting those features explicitly removes |
| 9 | the unused `yaml-rust`, `plist`, and `quick-xml` dependency path. The embedded |
| 10 | YAML language grammar remains available for highlighting YAML code blocks. |
| 11 | |
| 12 | `derivative`, `fxhash`, `paste`, and `ttf-parser` are absent from the Core lockfile. |
| 13 | Their obsolete advisory exceptions are removed so a future reintroduction is |
| 14 | visible to the advisory checks. No `cargo-audit` advisory is ignored. |
| 15 | |
| 16 | The remaining `cargo-deny` maintenance exception is |
| 17 | [RUSTSEC-2025-0141](https://rustsec.org/advisories/RUSTSEC-2025-0141.html) |
| 18 | for `bincode` 1.3.3. Syntect 5.3.0 requires it to deserialize its compiled-in |
| 19 | syntax and theme assets and for its parser's internal lazy-context encoding. |
| 20 | Codewhale does not pass arbitrary external dump files to these loaders. The |
| 21 | maintenance warning remains visible in `cargo-audit`; the lack of an identified |
| 22 | exploit in this advisory does not guarantee safety. |
| 23 | |
| 24 | Revisit the exception when upgrading or replacing Syntect, or before adding |
| 25 | external dump, grammar, or theme loading. Remove it when the dependency leaves |
| 26 | the graph. A replacement must preserve embedded language/theme coverage, |
| 27 | multiline highlighting and error recovery, and pass the existing Markdown |
| 28 | renderer tests with a resolver-verified lockfile. Adding ignores for new |
| 29 | advisories requires a separate assessment. |
| 30 | |
| 31 | The Apps desktop lockfile and its platform dependencies are a separate graph; |
| 32 | this Core cleanup does not resolve their maintenance or GLib qualification work. |
| 33 | |
| 34 | Automatic Git review and workspace polling require the runtime configuration |
| 35 | override interface introduced in [Git 2.31](https://github.com/git/git/blob/master/Documentation/RelNotes/2.31.0.adoc). The shared read authority probes the |
| 36 | resolved absolute executable once per process and pins subsequent commands to |
| 37 | that executable even if PATH changes. It refuses automatic reads if the executable |
| 38 | cannot honor those overrides; explicit user Git writes retain their existing behavior. |
| 39 | The porcelain-v1 display fallback does not waive this safety requirement. |
| 40 | The absolute path fixes executable search selection; it does not authenticate an |
| 41 | executable replaced at that path by the same local user. |
| 42 | |
| 43 | Local fixtures cover native modern Git and an emulated executable that ignores |
| 44 | runtime overrides. They do not qualify a real older-Git installation, partial |
| 45 | clones, or all platform-specific Git behavior. |
| 46 |