Skip to content

fix(deps): upgrade ratatui to resolve lru vulnerability - #4131

Merged
johntmyers merged 1 commit into
mainfrom
fix/dependabot-3-lru/alangou
Oct 2, 2026
Merged

johntmyers merged 1 commit into
mainfrom
fix/dependabot-3-lru/alangou

Conversation

@alangou

@alangou alangou commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

Remove the vulnerable lru 0.12.5 dependency used by the TUI by upgrading ratatui from 0.26.3 to 0.30.2, which resolves lru 0.18.5. Older ratatui releases constrain lru to the affected 0.12 series, so updating the transitive dependency alone cannot address the alert.

Related Issue

Addresses Dependabot alert #3.
Upstream advisory: GHSA-rhfx-m35p-ff5j, patched starting with lru 0.16.3.

Changes

  • Upgrade ratatui with the crossterm, layout-cache, and underline-color features; refresh its dependency graph in Cargo.lock. The larger lockfile diff includes ratatui's split crates and optional backend dependencies.
  • Replace deprecated Frame::size() calls with Frame::area() and buffer access with indexing in a rendering test.
  • Update the related TUI comment and contributor skill.
  • Preserve existing packages' windows-sys dependency versions.

Testing

  • TUI unit tests: 87 passed.
  • TUI Clippy with --all-targets -- -D warnings.
  • cargo fmt -p openshell-tui -- --check.
  • cargo check --locked --offline -p openshell-cli.
  • Locked, offline dependency resolution for Windows x64, Windows ARM64, and Linux after preserving windows-sys references.
  • Confirmed the only resolved lru version is 0.18.5; git diff --check passes.
  • Manual validation by the contributor against a running local gateway: TUI startup in light mode, navigation, sandbox/log views, forms, resizing including overlays, and clean exit.
  • No new tests were added; existing rendering tests were adapted to the updated API. Full sandbox E2E and native Windows builds were not run.

Checklist

  • Follows Conventional Commits.
  • Commits are signed off (DCO).
  • Related TUI contributor guidance updated.
  • Architecture documentation changes are not applicable.

Signed-off-by: Adrien Langou <alangou@nvidia.com>
@alangou alangou added the test:e2e Requires end-to-end coverage label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Label test:e2e applied for c0b9029. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers
johntmyers added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit d0a4e19 Oct 2, 2026
95 of 96 checks passed
@johntmyers
johntmyers deleted the fix/dependabot-3-lru/alangou branch October 2, 2026 21:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants