Skip to content

tdx: bump the serde_with crate to 3.23.0 to fix 3rd Party CVE issue. - #23

Merged
guzongmin merged 1 commit into
mainfrom
zhoul1/dev/OpenCVE_1
Sep 15, 2026
Merged

guzongmin merged 1 commit into
mainfrom
zhoul1/dev/OpenCVE_1

Conversation

@liangzhou121

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Regenerate and commit fuzz/Cargo.lock so supported fuzz builds no longer resolve the vulnerable version.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This pull request bumps serde_with to 3.23.0 to address a third-party CVE.

Changes:

  • Updates the workspace dependency.
  • Refreshes the root lockfile dependencies.
  • The separate fuzz lockfile still requires regeneration.
File summaries
File Summary
Cargo.toml Updates the workspace serde_with version.
Cargo.lock Records the updated root dependency resolution; the fuzz workspace remains on 3.18.0.
Review details
  • Files reviewed: 1/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Cargo.toml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The hypervisor manifest has a critical Cargo parsing error that must be fixed.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 3/5 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread hypervisor/Cargo.toml Outdated

@guzongmin guzongmin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@guzongmin
guzongmin merged commit 88a861d into main Sep 15, 2026
17 of 43 checks passed
Signed-off-by: Liang, Zhou <liang1.zhou@intel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants