Skip to content

[Security] rustls-webpki GHSA-82j2-j2ch-gfr8 still present in temporalio 1.26.0 wheel #1485

@cyridae

Description

@cyridae

Hello,

Our container vulnerability scan is reporting GHSA-82j2-j2ch-gfr8 / RUSTSEC-2026-0104 from the Rust dependency rustls-webpki bundled inside the temporalio Python wheel.

RUSTSEC-2026-0104 / GHSA-82j2-j2ch-gfr8 affects rustls-webpki and is patched in 0.103.13.

Could the SDK's Rust bridge dependencies be updated so the published Python wheels include rustls-webpki >=0.103.13, and could a new temporalio release be published with that fix?

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions