Skip to content

security: track transitive glib VariantStrIter advisory #267

Description

@DJJones66

Summary

Dependabot alert #77 reports GHSA-wrw7-89jp-8q8g against glib 0.18.5 in builds/typescript/src-tauri/Cargo.lock. The advisory affects the VariantStrIter iterator implementation and is patched in glib 0.20.0.

Current dependency path

The vulnerable crate is transitive through the Linux desktop stack:

braindrive-desktop
└── tauri 2.11.2
    └── gtk 0.18.2
        └── glib 0.18.5

BrainDrive's Rust source does not directly reference glib, VariantStrIter, Variant, or g_variant APIs. That reduces direct reachability, but it does not prove that no transitive GTK/Tauri path can invoke the affected iterator.

Upgrade evidence

A compatible direct update is not currently resolvable:

cargo update -p glib@0.18.5 --precise 0.20.0 --dry-run

error: failed to select a version for `glib = "^0.18"`
required by `gtk v0.18.2`

A dry run against the current Tauri patch line updates Tauri-related crates but does not provide a GTK/glib 0.20 transition. A [patch] or forced-version override would violate gtk 0.18.2's dependency contract and is not an acceptable remediation.

Current disposition

Closure criteria

  • A supported Tauri/GTK release resolves to glib >=0.20.0, or upstream backports the fix to the compatible 0.18 line.
  • Update the Tauri/GTK dependency chain without overrides that violate crate requirements.
  • cargo tree -i glib --locked confirms no vulnerable glib version remains.
  • cargo test --locked passes.
  • npm run desktop:preflight passes.
  • Linux desktop build/smoke verification passes.
  • Dependabot alert chore(deps-dev): bump typescript from 5.9.3 to 6.0.3 in /builds/typescript #77 closes from the patched lockfile.

Related remediation

The separate dependency-security change updates the compatible serde_with advisory and all currently patchable npm alerts. This issue tracks only the blocked glib dependency-chain remediation.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions