Repository navigation
chore(deps): bump rustls to 0.23.45 (GHSA-2mjx-qc3c-rqvc) - #124
Merged
Merged
Conversation
rustls < 0.23.45 accepts TLS 1.3 handshake messages across encryption level boundaries. rustls is a transitive dependency via reqwest, so this is a lockfile-only update; every dependent's version requirement already allows 0.23.45. rustls-webpki moves from 0.103.13 to 0.103.15 because rustls 0.23.44+ requires ^0.103.14. Dependabot could not resolve the two together (security_update_not_possible, capped at 0.23.43). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
jpage-godaddy
requested review from
axburgess-godaddy,
mguerrero3-godaddy,
qcai-godaddy,
rts1-godaddy and
runruh-godaddy
as code owners
October 8, 2026 18:16
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes Dependabot alert #2 (GHSA-2mjx-qc3c-rqvc, medium): rustls
>= 0.23.13, < 0.23.45accepts TLS 1.3 handshake messages across encryption level boundaries.rustls0.23.40 → 0.23.45 (patched)rustls-webpki0.103.13 → 0.103.15 (rustls 0.23.44+ requires^0.103.14)tempfilenow resolvesgetrandom 0.3.4instead of0.4.2(cargo re-resolution side effect; dev/test tooling only)Cargo.lockonly.rustlsis a transitive dependency viareqwest, and every dependent's requirement (^0.23,^0.23.4,^0.23.27) already allows 0.23.45, so no manifest changes were needed.Why not Dependabot
The Dependabot security job failed with
security_update_not_possible(latest-resolvable0.23.43, no conflicting dependencies). 0.23.43 is the last rustls compatible with the lockedrustls-webpki0.103.13, and Dependabot did not move that second crate.cargo update -p rustls --precise 0.23.45resolves both together.Test plan
cargo clippy --all-targets -- -D warningscargo test --all-targets🤖 Generated with Claude Code