Skip to content

fix: Bump MSRV to 1.96.0 and fix release-binary paths - #326

Merged
scouten-adobe merged 2 commits into
mainfrom
fix-msrv-and-audit-and-release-workflow
Sep 14, 2026
Merged

scouten-adobe merged 2 commits into
mainfrom
fix-msrv-and-audit-and-release-workflow

Conversation

@scouten-adobe

Copy link
Copy Markdown
Collaborator

Summary

The first real train cut for this repo (0.28.0-rc, tracking c2pa-rs's 0.91.0-rc) surfaced three separate, previously-latent problems — none caused by the cut itself, just never exercised before:

  • MSRV mismatch: c2pa-rs's breaking train raised its own rust-version to 1.96.0. This bumps Cargo.toml's rust-version, the Tier 1A MSRV matrix leg (1.88.0 → 1.96.0), docs/support-tiers.md, and the WASI/rustfmt nightly pins (nightly-2026-01-16 reports rustc 1.94.0-nightly, below the new floor; switched to nightly-2026-07-12, which c2pa-rs's own CI already uses and reports 1.99.0-nightly).
  • License/vulnerability audit failure: refreshing the c2pa dependency (cargo update -p c2pa, then -p rustls) picks up rustls 0.23.45, fixing a real advisory (TLS 1.3 handshake messages accepted across encryption-level boundaries) that the previously-locked 0.23.44 was exposed to. c2pa-rs itself already pins 0.23.45.
  • Broken release-binary build: c2patool-release.yml still did cd cli && make release / cd cli && cargo sbom, and the Makefile's release targets referenced ../target — both leftover from when this crate lived in a cli/ subdirectory. It's been at the repo root for a while, so cd cli was failing immediately, and simply removing it would have pointed ../target outside the repo entirely. Fixed both together: dropped cd cli, repointed the Makefile at target directly. Verified locally (make build-release-mac-arm produces the binary at the expected path).

Verified locally: cargo check --all-features, cargo test --all-features, cargo +nightly-2026-07-12 fmt --all -- --check, and cargo deny check (advisories/bans/licenses/sources all green) all pass.

Test plan

  • CI passes on this PR
  • Re-cut 0.28.0-rc from main after this merges and confirm Tier 1A and the binary-release build are green

🤖 Generated with Claude Code

scouten-adobe and others added 2 commits September 14, 2026 13:36
c2pa-rs's breaking train (0.91.0) raised its own rust-version to
1.96.0. Match it here: bump Cargo.toml's rust-version, the Tier-1A
MSRV matrix leg, and the WASI/rustfmt nightly pins (nightly-2026-01-16
reports rustc 1.94.0-nightly, below the new floor; nightly-2026-07-12
matches what c2pa-rs itself already uses and reports 1.99.0-nightly).

Also refreshes Cargo.lock (`cargo update -p c2pa` then `-p rustls`),
which incidentally fixes a real advisory: the previously-locked
rustls 0.23.44 trips a TLS 1.3 handshake-boundary vulnerability that
0.23.45 (already used by c2pa-rs) does not.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
c2patool-release.yml still did `cd cli && make release` / `cd cli &&
cargo sbom`, and the Makefile's release targets all referenced
`../target`, both leftover from when this crate lived in a `cli/`
subdirectory. It now lives at the repo root, so `cd cli` no longer
exists (it was silently failing every step after it) and `../target`
would resolve outside the repo entirely once that `cd` is removed.
Drop the `cd cli` prefix and point the Makefile at `target` directly.

This is c2patool's first tag-triggered release build, so this bug had
never actually been exercised until now.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
@scouten-adobe scouten-adobe changed the title fix: bump MSRV to 1.96.0, fix rustls advisory, and repair release-binary paths fix: Bump MSRV to 1.96.0 and fix release-binary paths Sep 14, 2026
@codecov

codecov Bot commented Sep 14, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.16%. Comparing base (e418a9f) to head (966ce2d).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #326   +/-   ##
=======================================
  Coverage   72.16%   72.16%           
=======================================
  Files           4        4           
  Lines        1060     1060           
=======================================
  Hits          765      765           
  Misses        295      295           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@scouten-adobe
scouten-adobe merged commit 7914428 into main Sep 14, 2026
17 of 18 checks passed
@scouten-adobe
scouten-adobe deleted the fix-msrv-and-audit-and-release-workflow branch September 14, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant