Skip to content

update rustls-webpki to 0.103.13 to resolve RUSTSEC-2026-0104#421

Merged
jadamcrain merged 1 commit into
mainfrom
update-rustls-webpki-0.103.13
May 7, 2026
Merged

update rustls-webpki to 0.103.13 to resolve RUSTSEC-2026-0104#421
jadamcrain merged 1 commit into
mainfrom
update-rustls-webpki-0.103.13

Conversation

@jadamcrain
Copy link
Copy Markdown
Member

Summary

  • Bumps rustls-webpki 0.103.12 → 0.103.13 to clear RUSTSEC-2026-0104 (reachable panic in CRL parsing).
  • The vulnerable code path is not reached by this codebase — no CRLs are constructed or passed into webpki anywhere in dnp3, the FFI bindings, or sfio-rustls-config. No runtime exposure for consumers; lockfile-only update to clear the scheduled security audit.

Reachable panic in CRL parsing. The vulnerable path is not reached by
this codebase (no CRLs are constructed or passed to webpki), but the
lockfile bump clears the scheduled security audit.
Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the rustls-webpki dependency in Cargo.lock from version 0.103.12 to 0.103.13. I have no feedback to provide as there are no review comments to evaluate.

@jadamcrain jadamcrain merged commit 66f8781 into main May 7, 2026
32 checks passed
@jadamcrain jadamcrain deleted the update-rustls-webpki-0.103.13 branch May 7, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant