From ee83d8ed55b30097f310ce87cca39150fac03d4b Mon Sep 17 00:00:00 2001 From: Mike Odnis Date: Mon, 21 Sep 2026 15:37:45 -0400 Subject: [PATCH] fix(deps): bump rustls to 0.23.45 for RUSTSEC-2026-0285 The osv-scanner job fails on main and on every PR branched from it: | https://osv.dev/RUSTSEC-2026-0285 | 5.3 | crates.io | rustls | 0.23.37 | 0.23.45 | Cargo.lock | ##[error]Process completed with exit code 1 rustls 0.23.37 accepts TLS 1.3 handshake messages that cross an encryption level boundary within a single record, which RFC 8446 section 5.1 requires be rejected with an unexpected_message alert. Fixed upstream in 0.23.45. Unlike the 11 advisories in osv-scanner.toml, this one has a released fix, so it is bumped rather than suppressed. cargo update -p rustls --precise 0.23.45 rustls-webpki moves with it because rustls 0.23.45 requires >= 0.103.14 and the lock held 0.103.13. Those two entries are the entire diff; the package count is unchanged at 796. --- Cargo.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 65ccb2d..74b5dcd 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -4354,9 +4354,9 @@ dependencies = [ [[package]] name = "rustls" -version = "0.23.37" +version = "0.23.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "758025cb5fccfd3bc2fd74708fd4682be41d99e5dff73c377c0646c6012c73a4" +checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634" dependencies = [ "once_cell", "ring", @@ -4417,9 +4417,9 @@ checksum = "f87165f0995f63a9fbeea62b64d10b4d9d8e78ec6d7d51fb2125fda7bb36788f" [[package]] name = "rustls-webpki" -version = "0.103.13" +version = "0.103.15" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e" +checksum = "f3c3cf1d8b1e7d4927e2d154c3fcb02979afb9939629c62cd9048d4f07b60ac2" dependencies = [ "ring", "rustls-pki-types",