chore(deps): bump toml from 0.8.23 to 1.1.4+spec-1.1.0 - #522
Merged
TinySweeper / tinysweeper/security
succeeded
Aug 9, 2026 in 0s
The pull request bumps the `toml` dependency from `"0.8"` to `"1"` in Cargo.toml
The pull request bumps the toml dependency from "0.8" to "1" in Cargo.toml. Both earlier findings still stand: there is no Cargo.lock update in the diff, and the major-version bump requires verifying that toml v1 is published and that call sites are updated for breaking changes — especially any that deserialize untrusted TOML. No new security findings beyond those already raised. (2 earlier finding(s) still open) The code index for this repository is cold, so this review saw the diff alone.
No findings.
Loading