Skip to content

Security: Mitigate tauri-utils advisory chain (urlpattern/unic/fxhash) #13

@saagar210

Description

@saagar210

Tracking unmaintained advisory chain through tauri-utils and related parser crates.

Advisories in this track:

  • RUSTSEC-2025-0057 (fxhash)
  • RUSTSEC-2025-0075
  • RUSTSEC-2025-0080
  • RUSTSEC-2025-0081
  • RUSTSEC-2025-0098
  • RUSTSEC-2025-0100

Current dependency chain evidence:

  • tauri-utils -> kuchikiki/selectors -> fxhash
  • tauri-utils -> urlpattern -> unic* crates

Planned mitigation path:

  1. Track tauri-utils upstream for replacement/removal of affected crates.
  2. Validate whether optional features can be pruned without functional regression.
  3. Remove waivers as upstream patches become available.

Parent issue: #11

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions