Skip to content

fix: update rustls-webpki to resolve GHSA-82j2-j2ch-gfr8#2

Open
dannyneira wants to merge 1 commit into
masterfrom
independabot/rustls-webpki-ghsa-82j2-j2ch-gfr8
Open

fix: update rustls-webpki to resolve GHSA-82j2-j2ch-gfr8#2
dannyneira wants to merge 1 commit into
masterfrom
independabot/rustls-webpki-ghsa-82j2-j2ch-gfr8

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

Vulnerabilities

Changes

  • rustls: 0.21 -> 0.23
  • rustls-pemfile: 1.0 -> 2.2
  • rustls-webpki: 0.101.4 -> 0.103.13
  • webpki-roots: 0.22.3 -> 1.0
  • Updated direct and transitive Rustls usage so cargo tree --all-features -i rustls-webpki resolves only rustls-webpki v0.103.13.

Verification

  • cargo fmt --check
  • cargo build --all-features
  • cargo test --all-features
  • cargo audit (no rustls-webpki vulnerability reported; existing allowed warnings remain for async-std and rustls-pemfile unmaintained advisories)

Conversation: https://staging.warp.dev/conversation/4c886604-4fe8-423f-b872-ee47b09f53d0
Run: https://oz.staging.warp.dev/runs/019e3184-23a2-70e5-b795-0116e7119a7f
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira marked this pull request as ready for review May 21, 2026 15:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant