Skip to content

fix(deps): update rustls-webpki to 0.103.10 (medium GHSA-pwjx-qhcg-rvj4)#223

Merged
louisliu2048 merged 1 commit intomainfrom
fix/security-rustls-webpki-19
Mar 26, 2026
Merged

fix(deps): update rustls-webpki to 0.103.10 (medium GHSA-pwjx-qhcg-rvj4)#223
louisliu2048 merged 1 commit intomainfrom
fix/security-rustls-webpki-19

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

Description

Bumps rustls-webpki to resolve a medium severity vulnerability.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)

Security Alert

Change

Updated rustls-webpki from 0.103.9 to 0.103.10 in Cargo.lock (transitive dependency). Only the version string and checksum were changed; dependency graph is unchanged.

Checklist

  • I have reviewed the relevant code guidelines in the docs/ folder
  • My code follows the coding standards of this project
  • I have performed a self-review of my own code

Bumps rustls-webpki from 0.103.9 to 0.103.10 to resolve a medium
severity vulnerability (faulty CRL matching logic against distribution
points).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@Vui-Chee Vui-Chee self-requested a review March 26, 2026 03:05
@louisliu2048 louisliu2048 merged commit 6f61586 into main Mar 26, 2026
@Vui-Chee Vui-Chee deleted the fix/security-rustls-webpki-19 branch March 26, 2026 03:07
@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 4, 2026

@Robot review

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request...

@XLayer-Bot
Copy link
Copy Markdown


Summary: Dependency-only patch that bumps rustls-webpki from 0.103.9 → 0.103.10 in Cargo.lock to resolve GHSA-pwjx-qhcg-rvj4 — a medium-severity vulnerability involving faulty CRL (Certificate Revocation List) distribution point matching logic. No source code changes, no Rust files modified.

Issues: None.

Positives:

  • Minimal, surgical change: only version string and checksum updated in Cargo.lock; dependency graph is identical.
  • Correct conventional commit message (fix(deps): ...) with CVE reference.
  • PR description is thorough — links the Dependabot alert, states severity, specifies the affected and fixed version ranges.
  • Transitive-only update means zero risk of API breakage.

Verdict: LGTM — safe to merge as-is.

@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@ci

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request cc9fe31

@XLayer-Bot
Copy link
Copy Markdown

XLayer Reth CI failed for commit cc9fe3129884e517a45e02ab1c19dc4bec277724

Step Result
format-check ⏩ skipped
compile-check ⏩ skipped
clippy ⏩ skipped
tests ⏩ skipped

View run

@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@ci

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request cc9fe31

@XLayer-Bot
Copy link
Copy Markdown

XLayer Reth CI failed for commit cc9fe3129884e517a45e02ab1c19dc4bec277724

Step Result
format-check ⏩ skipped
compile-check ⏩ skipped
clippy ⏩ skipped
tests ⏩ skipped

View run

@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@ci

1 similar comment
@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@ci

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request cc9fe31

@XLayer-Bot
Copy link
Copy Markdown

XLayer Reth CI failed for commit cc9fe3129884e517a45e02ab1c19dc4bec277724

Step Result
format-check ⏩ skipped
compile-check ⏩ skipped
clippy ⏩ skipped
tests ⏩ skipped

View run

@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@Agent-CI

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request cc9fe31

@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@ci

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request cc9fe31

@XLayer-Bot
Copy link
Copy Markdown

XLayer Reth CI failed for commit cc9fe3129884e517a45e02ab1c19dc4bec277724

Step Result
format-check ⏩ skipped
compile-check ⏩ skipped
clippy ⏩ skipped
tests ⏩ skipped

View run

@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@ci

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request for cc9fe31
workflow_file = xlayer-reth-ci.yml, repo = xlayer-reth, issue = 223

@XLayer-Bot
Copy link
Copy Markdown

XLayer Reth CI failed for commit cc9fe3129884e517a45e02ab1c19dc4bec277724

Step Result
format-check ✅ success
compile-check ✅ success
clippy ✅ success
tests ⚠️ cancelled

View run

@Vui-Chee
Copy link
Copy Markdown
Contributor

Vui-Chee commented Apr 5, 2026

@ci

@XLayer-Bot
Copy link
Copy Markdown

⏳ Robot is processing your request for cc9fe31
workflow_file = xlayer-reth-ci.yml, repo = xlayer-reth, issue = 223

@XLayer-Bot
Copy link
Copy Markdown

XLayer Reth CI failed for commit cc9fe3129884e517a45e02ab1c19dc4bec277724

Step Result
format-check ✅ success
compile-check ✅ success
clippy ✅ success
tests ⚠️ cancelled

View run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants