Skip to content

update dependency#173

Draft
emig wants to merge 1 commit into
mainfrom
fix/dependabot_alerts
Draft

update dependency#173
emig wants to merge 1 commit into
mainfrom
fix/dependabot_alerts

Conversation

@emig
Copy link
Copy Markdown
Collaborator

@emig emig commented Apr 22, 2026

Updates aws-lc-rs, after multiple dependabot high alerts by updating aws-lc-rs.
The alerts refer to functionality of the library not used by criticalup code.
As an extra improvement the update removes a many dependencies.

https://github.com/ferrocene/criticalup/security/dependabot/15 High
#15 opened last month • Detected in aws-lc-sys (Rust) • Cargo.lock
Select alert: AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
https://github.com/ferrocene/criticalup/security/dependabot/16 High
#16 opened last month • Detected in aws-lc-sys (Rust) • Cargo.lock
Select alert: AWS-LC has PKCS7_verify Signature Validation Bypass
https://github.com/ferrocene/criticalup/security/dependabot/17 High
#17 opened last month • Detected in aws-lc-sys (Rust) • Cargo.lock
Select alert: CRL Distribution Point Scope Check Logic Error in AWS-LC
https://github.com/ferrocene/criticalup/security/dependabot/21 High

cargo update aws-lc-rs

> cargo update aws-lc-rs
@emig
Copy link
Copy Markdown
Collaborator Author

emig commented Apr 22, 2026

bors try

bors-ferrocene Bot added a commit that referenced this pull request Apr 22, 2026
@bors-ferrocene
Copy link
Copy Markdown
Contributor

try

Build succeeded:

@emig emig requested review from Dajamante and Hoverbear April 22, 2026 11:14
@emig emig marked this pull request as draft May 5, 2026 08:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants