Skip to content

Build postcard without its default features (drops heapless / atomic-polyfill, RUSTSEC-2023-0089) - #111

Open
alexandru-diaconu wants to merge 1 commit into
whisperfish:mainfrom
alexandru-diaconu:postcard-without-default-features
Open

alexandru-diaconu wants to merge 1 commit into
whisperfish:mainfrom
alexandru-diaconu:postcard-without-default-features

Conversation

@alexandru-diaconu

Copy link
Copy Markdown

postcard's default feature heapless-cas pulls in heapless 0.7, which depends on atomic-polyfill, flagged as unmaintained by RUSTSEC-2023-0089. So every downstream cargo audit / cargo deny run reports it, although this crate never uses heapless.

The crate only needs postcard::from_bytes at runtime (src/metadata/database.rs) and to_io with use-std in build.rs. This PR turns the default features off in both places:

  • [dependencies]: postcard = { version = "1.1", default-features = false }
  • [build-dependencies]: postcard = { version = "1.1", default-features = false, features = ["use-std"] }

Verified:

  • On current main, cargo test passes unchanged: 90 unit tests, plus the doc and integration tests.
  • cargo tree -i heapless and cargo tree -i atomic-polyfill now match no package.

Thanks for maintaining this crate.

🤖 Generated with Claude Code

Only postcard::from_bytes is used at runtime (src/metadata/database.rs), and
build.rs only needs use-std. postcard's default feature `heapless-cas` pulls in
heapless 0.7, which depends on atomic-polyfill, flagged unmaintained by
RUSTSEC-2023-0089. Every downstream `cargo audit` / `cargo deny` then reports it,
although nothing here uses heapless.

With default-features = false the full test suite passes unchanged and neither
heapless nor atomic-polyfill remains in the dependency graph.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant