Skip to content

chore(deps): bump aws-lc-sys to 0.38.0 (security)#191

Merged
NormB merged 1 commit into
mainfrom
fix/update-aws-lc-sys
Mar 12, 2026
Merged

chore(deps): bump aws-lc-sys to 0.38.0 (security)#191
NormB merged 1 commit into
mainfrom
fix/update-aws-lc-sys

Conversation

@NormB
Copy link
Copy Markdown
Owner

@NormB NormB commented Mar 12, 2026

Summary

Test plan

  • cargo check passes
  • CI pipeline passes (ShellCheck, Trivy, Clippy, CodeQL, unit/integration tests)

🤖 Generated with Claude Code

Fixes three high-severity security advisories:
- GHSA aws-lc-sys: PKCS7_verify Signature Validation Bypass
- GHSA aws-lc-sys: Timing Side-Channel in AES-CCM Tag Verification
- GHSA aws-lc-sys: PKCS7_verify Certificate Chain Validation Bypass

Updates aws-lc-rs 1.15.0 -> 1.16.1 which pulls in aws-lc-sys 0.38.0.
@NormB NormB merged commit b0de4b2 into main Mar 12, 2026
30 of 31 checks passed
@NormB NormB deleted the fix/update-aws-lc-sys branch March 12, 2026 03:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant