You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Update rustls to fix TLS handshake validation #1002
The current lockfile resolves rustls 0.23.44, affected by RUSTSEC-2026-0285 / GHSA-2mjx-qc3c-rqvc. Rustls can accept TLS 1.3 handshake messages across encryption-level boundaries when messages share a record. Upstream fixes this in 0.23.45; the affected range is 0.23.13 through 0.23.44.
The advisory makes cargo audit fail in PR #1001's CI, preventing the dependent unit/CLI and Docker E2E jobs from running. Prioritize this security update before the independent Dependabot grouping PR #1001.
Scope and acceptance criteria
Update the resolved rustls version to 0.23.45, the patched release, using a targeted Cargo update. The existing Cargo.toml constraint 0.23 already permits it.
Keep unrelated dependencies and application behavior unchanged. Include additional lockfile changes only if required by resolution of the patched release.
Add a concise security changelog entry describing the corrected TLS handshake validation, since the last released version also carries affected rustls code.
Preserve certificate verification, TLS policies, and existing audit checks. Do not suppress the advisory or weaken CI.
Confirm the lockfile resolves the patched version and inspect the dependency diff.
Run cargo audit and confirm RUSTSEC-2026-0285 no longer appears as a vulnerability.
Run the repository quality checks and local preflight, including the Docker E2E matrix. If a local environmental prerequisite blocks the matrix, run as far as possible and document the exact local results and limitation, leaving CI to gate the remaining coverage under AGENTS.md.
Require the PR's Quality Check, unit/CLI tests, Docker E2E matrix, and CodeQL checks to finish successfully before handoff.
After this PR is merged by a maintainer, bring its fix into #1001 and rerun that PR's CI as the lower-priority follow-up.
Problem
The current lockfile resolves
rustls 0.23.44, affected by RUSTSEC-2026-0285 / GHSA-2mjx-qc3c-rqvc. Rustls can accept TLS 1.3 handshake messages across encryption-level boundaries when messages share a record. Upstream fixes this in0.23.45; the affected range is0.23.13through0.23.44.The advisory makes
cargo auditfail in PR #1001's CI, preventing the dependent unit/CLI and Docker E2E jobs from running. Prioritize this security update before the independent Dependabot grouping PR #1001.Scope and acceptance criteria
rustlsversion to0.23.45, the patched release, using a targeted Cargo update. The existingCargo.tomlconstraint0.23already permits it.Validation
cargo auditand confirm RUSTSEC-2026-0285 no longer appears as a vulnerability.After this PR is merged by a maintainer, bring its fix into #1001 and rerun that PR's CI as the lower-priority follow-up.