Bump rustls to 0.23.45 for RUSTSEC-2026-0285 - #262
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Why
cargo auditis a required status check onmain, and it has been failing onmainitself since #258 landed (run 35634534809 on 2be34c6). The failure has nothing to do with #258's diff: the RustSec advisory database published RUSTSEC-2026-0285 againstrustlsin the meantime, and Splitrail's lockfile pinsrustls 0.23.36.Because the check is required, every open PR fails it no matter what it changes, and no release PR can merge until
mainis fixed.rustlsis on Splitrail's real network path:reqwestuses it for the cloud upload client, so this is not a feature-gated false positive of the kind already documented in.cargo/audit.toml.What changed
A lockfile-only bump.
Cargo.tomlis untouched.rustlsrustls-webpkiaws-lc-rsaws-lc-sysThe
aws-lc-*bump is required, not incidental. A plaincargo update -p rustlsupdates onlyrustlsand stops at 0.23.43, because 0.23.44 and later need a neweraws-lc-rsthan the lockfile allows. Reaching the fixed version means moving the crypto backend with it, so this PR pins withcargo update -p rustls --precise 0.23.45. All four crates declarerust-version = 1.71, well below the nightly toolchain inrust-toolchain.toml.Risk
aws-lc-syscompiles a C library, which makes platform coverage the real risk in this bump. The PR'sTest (windows-latest)job covers the MSVC build. PR CI never builds the release workflow's cross-compiled Linux targets (aarch64/x86_64×gnu/musl), so all four were built locally withcross0.2.5 in isolated target directories; see Validation.Not changed
The remaining two advisories are unsoundness warnings, which
cargo auditreports without failing, and this PR leaves them alone:anyhow,Error::downcast_mut())lru,LruCache::pop()panic safety)Validation
cargo audit→ exit 0 (was:error: 1 vulnerability found!)cargo build --quietcargo test --quietcargo clippy --quiet --all-targets -- -D warningscross build --release --locked --target <t>foraarch64-unknown-linux-musl,aarch64-unknown-linux-gnu,x86_64-unknown-linux-gnu,x86_64-unknown-linux-musl: all four finished and produced ELF binaries of the right architecture