Skip to content

bump rustls-webpki 0.103.12 -> 0.103.13#183

Merged
dblodgett-usgs merged 1 commit into
mainfrom
patch-main
Apr 26, 2026
Merged

bump rustls-webpki 0.103.12 -> 0.103.13#183
dblodgett-usgs merged 1 commit into
mainfrom
patch-main

Conversation

@dblodgett-usgs
Copy link
Copy Markdown
Collaborator

Summary

  • Patches GHSA-82j2-j2ch-gfr8 (CVSS 7.5): rustls-webpki panic on malformed CRL BIT STRING.
  • Transitive dep via zarrs_http → reqwest → rustls. Bump is a single-line cargo update -p rustls-webpki.
  • Not exploitable in pizzarr (we never pass RevocationOptions), but clears the Dependabot alert.

Test plan

  • CI green on main after merge
  • r-universe rebuild picks up the patched lock

🤖 Generated with Claude Code

Patches GHSA-82j2-j2ch-gfr8 (CVSS 7.5): panic on malformed CRL
BIT STRING. pizzarr does not enable RevocationOptions, so not
exploitable here, but clears the Dependabot alert.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@dblodgett-usgs dblodgett-usgs merged commit 277ca5b into main Apr 26, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant