chore(deps): bump rustls from 0.23.35 to 0.23.36#68
chore(deps): bump rustls from 0.23.35 to 0.23.36#68dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps [rustls](https://github.com/rustls/rustls) from 0.23.35 to 0.23.36. - [Release notes](https://github.com/rustls/rustls/releases) - [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md) - [Commits](rustls/rustls@v/0.23.35...v/0.23.36) --- updated-dependencies: - dependency-name: rustls dependency-version: 0.23.36 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
|
Superseded by v0.4.1 (commit 7c8b5e1) which refreshed Cargo.lock with all latest compatible dependencies. This update is already included. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
GitHub Actions updates: - actions/upload-artifact v6 -> v7 (ci.yml, master-pipeline.yml x3, release.yml, security-audit.yml) - actions/download-artifact v7 -> v8 (ci.yml, master-pipeline.yml, release.yml) Dependabot PR cleanup (11 PRs closed): - Cargo PRs #68-#75, #78-#79: all dependency updates already incorporated via Cargo.lock refresh in v0.4.1 (webpki-roots 1.0.6, anyhow 1.0.102, bytes 1.11.1, mlua 0.11.6, thiserror 2.0.18, rustls-pki-types 1.14.0, chrono 0.4.44, tokio-test 0.4.5, rustls 0.23.37) - Actions PRs #81-#82: applied directly in this release Security issue resolution (3 issues closed): - Issue #76 (RUSTSEC-2026-0007 bytes): fixed in v0.4.1 - Issue #77 (RUSTSEC-2026-0009 time): upstream-pinned, in audit ignore - Issue #66 (RUSTSEC-2025-0141 bincode): informational, transitive via iced Security alert dismissal: - Alert #4 (time crate): dismissed as tolerable risk -- pinned at =0.3.45 by mac-notification-sys via notify-rust Repository state: 0 open PRs, 0 open issues, 0 open security alerts Version bump: 0.4.1 -> 0.4.2 across all 7 Cargo.toml files Verification: 266 tests passing, zero clippy warnings, zero fmt issues Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Bumps rustls from 0.23.35 to 0.23.36.
Commits
b47bf54Prepare 0.23.3699308d2Bump nightly toolchain for cargo-check-external-typesba00982Support P256+SHA512 and P384+SHA512 signatures in certificatesYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)