Skip to content

deps: bump russh from 0.63.1 to 0.63.3 - #224

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/russh-0.63.3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/russh-0.63.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Bumps russh from 0.63.1 to 0.63.3.

Release notes

Sourced from russh's releases.

v0.63.3

Fixes

  • c13b259: enforce inactivity timeout even during stalled writes (Eugene)

v0.63.2

Security fixes

GHSA-g4mp-vgx3-xrvm - out-of-bounds read in pageant

A malicious Pageant agent could cause an out-of-bounds read / oversized allocation in the pageant library user.

GHSA-35g8-35p8-c8fw - unbounded memory allocation in server

An authenticated client could trigger unbounded memory allocation during rekey phase

Fixes

  • client: encode the negotiated hash algorithm for RSA certificates (#764) #764 (Jeongkyu Shin)
  • 4206815: Fix pty-req terminal modes: deliver them unpadded, encode the right l… (#755) (tluyben) #755
  • b1d3893: fixed #762 - redact sensitive data from debug logging (Eugene)
  • 66789f4: fixed #761 - data write split across a kex breaks (Eugene)
  • a04e1b5: fixed #758 - fail RSA signing explicitly when RSA feature is not enabled (Eugene)
  • 422123c: dedup zlib compress loop into compress_into (Eugene)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [russh](https://github.com/warp-tech/russh) from 0.63.1 to 0.63.3.
- [Release notes](https://github.com/warp-tech/russh/releases)
- [Commits](Eugeny/russh@v0.63.1...v0.63.3)

---
updated-dependencies:
- dependency-name: russh
  dependency-version: 0.63.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 18, 2026
davekempe added a commit that referenced this pull request Sep 19, 2026
rustls 0.23.45, uuid 1.26.1, russh 0.63.3, tokio-rustls 0.26.5, aes 0.9.3,
rcgen 0.14.10, tower-http 0.7.1, toml 1.1.6. All are patch level within the
existing Cargo.toml constraints, so this is a lockfile-only change.

Two transitive majors ride along: rcgen takes pem 3.0.6 to 4.0.0, and rustls
takes aws-lc-rs 1.17.3 to 1.18.1 with aws-lc-sys 0.43.0 to 0.45.0. Release
build, 273 tests, clippy and cargo audit all clean.

Closes #215, #216, #217, #219, #224, #225, #226, #227.
@dependabot @github

dependabot Bot commented on behalf of github Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Looks like russh is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 19, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/russh-0.63.3 branch September 19, 2026 06:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants