Tracking unsound advisory in lru pulled transitively through Tantivy/Lance stack.
Advisories in this track:
Current dependency chain evidence:
- lru -> tantivy -> lance-index/lance/lancedb -> assistsupport
Planned mitigation path:
- Monitor tantivy/lance ecosystem for patched
lru dependency.
- Evaluate whether dependency override to fixed
lru is safe once upstream compatibility is confirmed.
- Remove waiver immediately after dependency graph update.
Parent issue: #11