Skip to content

chore(deps): bump rustls-webpki 0.103.12 -> 0.103.13 (RUSTSEC-2026-0104)#2956

Merged
michaeldwan merged 1 commit intomainfrom
md/fix-rustls-webpki-advisory
Apr 22, 2026
Merged

chore(deps): bump rustls-webpki 0.103.12 -> 0.103.13 (RUSTSEC-2026-0104)#2956
michaeldwan merged 1 commit intomainfrom
md/fix-rustls-webpki-advisory

Conversation

@michaeldwan
Copy link
Copy Markdown
Member

RUSTSEC-2026-0104 added a new advisory for rustls-webpki v0.103.12 -- a reachable panic when parsing certificate revocation lists. cargo-deny catches this and fails the "Lint Rust (deny)" CI job on every branch.

cargo update -p rustls-webpki bumps to 0.103.13 which has the fix. Lockfile-only change.

Fixes a reachable panic in CRL parsing that cargo-deny flags as a
vulnerability, breaking CI on every branch.
@michaeldwan michaeldwan requested a review from a team as a code owner April 22, 2026 16:26
@ask-bonk
Copy link
Copy Markdown
Contributor

ask-bonk Bot commented Apr 22, 2026

LGTM

github run

@michaeldwan michaeldwan enabled auto-merge April 22, 2026 16:28
@michaeldwan michaeldwan disabled auto-merge April 22, 2026 16:29
@michaeldwan michaeldwan merged commit 7956e7b into main Apr 22, 2026
27 checks passed
@michaeldwan michaeldwan deleted the md/fix-rustls-webpki-advisory branch April 22, 2026 16:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants