Merge pull request #51 from Coffey-Labs/fix/rustls-advisory

Update rustls to 0.23.45 for RUSTSEC-2026-0285
This commit is contained in:
jcoffey
2026-09-15 15:02:51 -07:00
committed by GitHub
2 changed files with 2 additions and 18 deletions
+2 -2
View File
@@ -823,9 +823,9 @@ dependencies = [
[[package]]
name = "rustls"
version = "0.23.43"
version = "0.23.45"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06"
checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634"
dependencies = [
"log",
"once_cell",
-16
View File
@@ -70,22 +70,6 @@ feature-depth = 1
# A list of advisory IDs to ignore. Note that ignored advisories will still
# output a note when they are encountered.
ignore = [
{ id = "RUSTSEC-2025-0134", reason = """
`rustls-pemfile` is unmaintained -- its repository was archived in
August 2025. A maintenance advisory, not a vulnerability: no CVE, no
known exploit, and the advisory itself states "No safe upgrade is
available".
It reaches us transitively (cairnobs-agent -> tonic 0.12.3 ->
rustls-pemfile 2.2.0), so there is nothing to fix on our side; the
upstream migration is tonic's to make, to the PemObject API that
rustls-pki-types has carried since 1.9.0. The last rustls-pemfile
release is a thin wrapper over that same code, so the archived crate is
not running different logic from its replacement.
Revisit when tonic is next upgraded -- check whether it has moved to
rustls-pki-types directly, and delete this entry if so rather than
letting it become permanent.""" },
#"RUSTSEC-0000-0000",
#{ id = "RUSTSEC-0000-0000", reason = "you can specify a reason the advisory is ignored" },
#"[email protected]", # you can also ignore yanked crate versions if you wish