Tracking unmaintained advisory chain through tauri-utils and related parser crates.
Advisories in this track:
- RUSTSEC-2025-0057 (fxhash)
- RUSTSEC-2025-0075
- RUSTSEC-2025-0080
- RUSTSEC-2025-0081
- RUSTSEC-2025-0098
- RUSTSEC-2025-0100
Current dependency chain evidence:
- tauri-utils -> kuchikiki/selectors -> fxhash
- tauri-utils -> urlpattern -> unic* crates
Planned mitigation path:
- Track tauri-utils upstream for replacement/removal of affected crates.
- Validate whether optional features can be pruned without functional regression.
- Remove waivers as upstream patches become available.
Parent issue: #11