Summary
Dependabot alert #77 reports GHSA-wrw7-89jp-8q8g against glib 0.18.5 in builds/typescript/src-tauri/Cargo.lock. The advisory affects the VariantStrIter iterator implementation and is patched in glib 0.20.0.
Current dependency path
The vulnerable crate is transitive through the Linux desktop stack:
braindrive-desktop
└── tauri 2.11.2
└── gtk 0.18.2
└── glib 0.18.5
BrainDrive's Rust source does not directly reference glib, VariantStrIter, Variant, or g_variant APIs. That reduces direct reachability, but it does not prove that no transitive GTK/Tauri path can invoke the affected iterator.
Upgrade evidence
A compatible direct update is not currently resolvable:
cargo update -p glib@0.18.5 --precise 0.20.0 --dry-run
error: failed to select a version for `glib = "^0.18"`
required by `gtk v0.18.2`
A dry run against the current Tauri patch line updates Tauri-related crates but does not provide a GTK/glib 0.20 transition. A [patch] or forced-version override would violate gtk 0.18.2's dependency contract and is not an acceptable remediation.
Current disposition
Closure criteria
Related remediation
The separate dependency-security change updates the compatible serde_with advisory and all currently patchable npm alerts. This issue tracks only the blocked glib dependency-chain remediation.
Summary
Dependabot alert #77 reports
GHSA-wrw7-89jp-8q8gagainstglib 0.18.5inbuilds/typescript/src-tauri/Cargo.lock. The advisory affects theVariantStrIteriterator implementation and is patched inglib 0.20.0.Current dependency path
The vulnerable crate is transitive through the Linux desktop stack:
BrainDrive's Rust source does not directly reference
glib,VariantStrIter,Variant, org_variantAPIs. That reduces direct reachability, but it does not prove that no transitive GTK/Tauri path can invoke the affected iterator.Upgrade evidence
A compatible direct update is not currently resolvable:
A dry run against the current Tauri patch line updates Tauri-related crates but does not provide a GTK/glib 0.20 transition. A
[patch]or forced-version override would violategtk 0.18.2's dependency contract and is not an acceptable remediation.Current disposition
not_used; transitive reachability has not been disproven.glib 0.20into the GTK 0.18 graph.Closure criteria
glib >=0.20.0, or upstream backports the fix to the compatible 0.18 line.cargo tree -i glib --lockedconfirms no vulnerable glib version remains.cargo test --lockedpasses.npm run desktop:preflightpasses.Related remediation
The separate dependency-security change updates the compatible
serde_withadvisory and all currently patchable npm alerts. This issue tracks only the blockedglibdependency-chain remediation.