chore(deps): resolve cargo audit advisories - #145
Conversation
RUSTSEC-2026-0285: rustls 0.23.37 incorrectly accepts TLS 1.3 handshake messages across encryption level boundaries. Bump to 0.23.45 (the patched release). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019j5JA1n6MdcHEUbRVnABXE
|
Claude finished @alukach's task in 48s —— View job Review complete
✅ No blocking issues — safe to merge. The diff is Verified the one thing worth double-checking in a lockfile-only PR — the No correctness or security concerns in the diff itself. The Simplify (ponytail) Nothing to flag — this is a mechanical 💰 Estimated review cost: $0.22 · 0m47s · 10 turns |
|
That's a Docker Hub pull failure for a base image the workflow always uses — the same job passed cleanly on Generated by Claude Code |
|
The Re-running Generated by Claude Code |
|
That rules out a one-off blip. It's not this PR's failure (diff is No existing PR fixes this. I'm not pushing a fix here since it'd widen this PR beyond the I've used my one re-run per the CI-failure policy; standing down on Generated by Claude Code |
|
Generated by Claude Code |
|
Summary of this PR's CI state: Generated by Claude Code |
|
Today's scheduled Two things worth a look before merging: this PR's own Generated by Claude Code |
|
Today's scheduled This PR's own Generated by Claude Code |
|
Ran the scheduled Flagging that this PR has been open since 2026-09-15 and CI is currently red (Audit + Integration Tests failing). Per the PR description, that's expected until #142 merges first — its own Audit job can't go green while Generated by Claude Code |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Folds in the remaining bumps from #142 (anyhow: RUSTSEC-2026-0190). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Good catches — updated the PR description to match the current diff: h2/anyhow/chacha20 are now fixed here too (folded in from #142), only
Generated by Claude Code |
|
Scheduled
Status update worth a human look: as of the last push to each branch, #142 is now the greener of the two — its Both PRs fix the same advisories and now overlap in their 🤖 Generated with Claude Code https://claude.ai/code/session_0164BBFUoSJjnJRteXFtna8c Generated by Claude Code |
What I'm changing
cargo auditonmain(25a90e2) reported two actual vulnerabilities:rustls0.23.37 incorrectly accepts TLS 1.3 handshake messages across encryption level boundaries (medium, CVSS 5.3). Published 2026-09-14, after chore(deps): resolve cargo audit advisories #142 was opened. This is what originally failed the CIAuditjob on this branch.h20.4.13's unbounded empty DATA frames (resource-exhaustion DoS). Originally tracked by chore(deps): resolve cargo audit advisories #142; folded into this branch too so this PR's ownAuditcheck is green independently.Both are transitive dependencies (
rustlsviareqwest/hyper-rustls/rustls-platform-verifier;h2viareqwest/object_store), so noCargo.tomlchanges were needed — justCargo.lockupdates within existing semver ranges.cargo auditalso reports non-blocking warnings (unsound/yanked, not CVEs) foranyhow,rand, andspin.anyhowandchacha20(yanked) are bumped below;randandspinare not — see "Not fixed."#142 closed: that PR tracked the same h2/anyhow/rand/chacha20 advisories; its fixes (minus
rand) are folded into this branch, so #142 was closed in favor of this PR rather than merging both.How I did it
cargo update -p rustls --precise 0.23.45— clears RUSTSEC-2026-0285. Pulledrustls-webpki0.103.13 → 0.103.15 andaws-lc-rs/aws-lc-sys(rustls's crypto provider) 1.17.1 → 1.18.1 / 0.42.0 → 0.45.0 along with it.cargo update -p h2 --precise 0.4.19— clears RUSTSEC-2026-0258.cargo update -p anyhow --precise 1.0.104— clears the RUSTSEC-2026-0190 unsound warning.cargo update -p chacha20 --precise 0.10.2— clears the yanked-crate warning.Cargo.lockalso resynced themultistore-*workspace-member entries from0.7.1to0.7.2, matching the version already set inCargo.toml— stale-lockfile side effect, not introduced by this PR.errno,quinn-udp,rustls-platform-verifier, andwinapi-utilmoved fromwindows-sys0.60.2/0.61.2 to 0.52.0 as a resolver side effect (ringhard-pinswindows-sys = "^0.52"). All threewindows-sysversions still coexist in the lockfile — nothing dropped. Windows-only, no known advisory on 0.52.0.mainin (2026-09-25) to pick up ci: replace MinIO with RustFS as the local/CI S3 backend #148 (MinIO → RustFS in CI, since Docker Hub stopped allowing anonymous pulls ofminio/minio) — this cleared theIntegration Testsfailures that blocked this branch for over a week.Not fixed
rand0.8.5/0.9.2, unsound) — a warning, not a blocking vulnerability (doesn't failcargo audit's exit code in this repo's config). Not bumped here.spin0.9.8 — yanked. Pulled in transitively vialazy_static(required byrsa→multistore-oidc-provider/multistore-sts), which pinsspin = "^0.9.8". The only newer release (0.10.1) is semver-incompatible with that requirement, so it can't be bumped without an upstream fix inlazy_static. Not a CVE, just a yank warning.Test plan
cargo audit— RUSTSEC-2026-0285 and RUSTSEC-2026-0258 both cleared; only therand/spinwarnings remain (non-blocking, see above)cargo checkcargo check -p multistore-cf-workers --target wasm32-unknown-unknowncargo testcargo fmt --checkcargo clippy -- -D warningsFormat,Cargo Check,Cargo Check (WASM),Clippy,Unit Tests,Audit,Integration Testsall green.Deploy & Test / Smoke Testis red for a pre-existing/unrelated reason (Cloudflare edge-cache flake on the shared range-test fixture, tracked across multiple prior PRs) — documented in PR comments.🤖 Generated with Claude Code
https://claude.ai/code/session_019j5JA1n6MdcHEUbRVnABXE
Generated by Claude Code