zeroize 1.9.0 stays exempt (322-zeroize in DECISIONS.md): optimization_barrier's non-asm fallback (src/barrier.rs:92-100) reads possibly-uninitialized bytes and the published acdp-wasm binding compiles that path. RustCrypto/utils#1535 (merged 2026-09-11) removes internal callers but barrier.rs on master is unchanged and 1.9.1 is unreleased. When 1.9.1 ships: delta-audit 1.9.0 -> 1.9.1; if the residual is only an unused safe pub fn it qualifies for the policy's discretion clause. The guard's marker is version-pinned (@1.9.0), so a hand-moved exemption fails CI. Upstream issue drafts (zeroize barrier UB; sha2 aarch64 vld1q_u32(&K32[t])) are text in the worksheets and are the maintainer's to file.
Follow-up from the #322 crypto re-certification (PRs #332, #334, #335, #336, #338; see DECISIONS.md "#322 completion status" and supply-chain/worksheets/).
zeroize1.9.0 stays exempt (322-zeroizein DECISIONS.md):optimization_barrier's non-asm fallback (src/barrier.rs:92-100) reads possibly-uninitialized bytes and the published acdp-wasm binding compiles that path. RustCrypto/utils#1535 (merged 2026-09-11) removes internal callers butbarrier.rson master is unchanged and 1.9.1 is unreleased. When 1.9.1 ships: delta-audit 1.9.0 -> 1.9.1; if the residual is only an unused safe pub fn it qualifies for the policy's discretion clause. The guard's marker is version-pinned (@1.9.0), so a hand-moved exemption fails CI. Upstream issue drafts (zeroize barrier UB; sha2 aarch64vld1q_u32(&K32[t])) are text in the worksheets and are the maintainer's to file.Follow-up from the #322 crypto re-certification (PRs #332, #334, #335, #336, #338; see DECISIONS.md "#322 completion status" and supply-chain/worksheets/).