Commit fabfe23
committed
fix(deps): patch security advisories in rustls-webpki, rand, h3
Closes 8 open dependabot alerts via transitive lockfile bumps:
- rustls-webpki 0.103.9 -> 0.103.13 — CRL/URI/wildcard name-constraint
handling and panic-on-malformed-CRL DoS (alerts #27 #42 #43 #47)
- rand 0.8.5 -> 0.8.6 and 0.9.2 -> 0.9.4 — soundness fix for callers
using a custom logger with rand::rng() (#45 #46)
- h3 1.15.8 -> 1.15.11 (website) — path traversal via double-decoded
%252e%252e in serveStatic and SSE event injection via unsanitized
carriage return (#24 #25)
No direct dependency edits; all bumps are transitive.1 parent a5dec01 commit fabfe23
2 files changed
Lines changed: 26 additions & 26 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments