Repository navigation
chore(rumqttc): update rustls-webpki to 0.103 - #1073
Closed
tinegachris wants to merge 1 commit into
Closed
tinegachris wants to merge 1 commit into
tinegachris wants to merge 1 commit into
Conversation
`rustls-webpki` is declared at 0.102.8, which is the last release of that line. Four advisories were filed against it and fixed only in 0.103.x: RUSTSEC-2026-0049, RUSTSEC-2026-0098, RUSTSEC-2026-0099 and RUSTSEC-2026-0104. A downstream project running `cargo deny` therefore has no version to move to and has to ignore all four, even though rumqttc itself parses no certificate with the crate: it is linked for the `TlsError::WebPki` variant alone, and verification is rustls's own, through the `rustls-webpki` 0.103 that `tokio-rustls` already pulls in. That also means the two versions sit in the same tree today, which the update collapses to one. No source change is needed; the crate builds unmodified against 0.103. Signed off: Chrispine Tinega <dev@chrispinetinega.com> Attribute: @tinegachris
|
Hi @tinegachris, and thanks for the PR, but this is a duplicate of #1037. |
Author
|
Thanks. Closing in favour of #1037. Two notes for whoever picks that one up, since it has been open since March and is
Happy to rebase and reopen if a one-line bump to |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
rustls-webpkiis declared at0.102.8, which is the last release of that line. Four advisories were filed against it and are fixed only in 0.103.x:A downstream project running
cargo denytherefore has no version to move to and has to ignore all four — even though rumqttc itself parses no certificate with the crate. It is linked for theTlsError::WebPkivariant alone; verification is rustls's own, through therustls-webpki0.103 thattokio-rustlsalready pulls in. That also means both versions sit in the same dependency tree today, which this collapses to one.No source change is needed. Checked with:
rumqttdis deliberately left alone: it declaresrustls-webpki0.102.2 andtokio-rustls0.25, so moving it is a breaking bump and a separate change.