Skip to content

chore(agent)(deps): bump russh from 0.63.3 to 0.64.1 in /catalyst-agent in the rust-major group across 1 directory - #288

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/catalyst-agent/rust-major-db36a3918a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/catalyst-agent/rust-major-db36a3918a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the rust-major group with 1 update in the /catalyst-agent directory: russh.

Updates russh from 0.63.3 to 0.64.1

Release notes

Sourced from russh's releases.

v0.64.1

Security fixes

GHSA-4wc5-f2rc-q74m - Unbounded memory allocation in agent protocol server via crafted constraint records

A local actor or a connected remote server (that the user forwards an agent connection to) can trigger an unlimited memory allocation in a russh-based SSH agent via a crafted message.

v0.64.0

Breaking changes

  • 5d9d2b8: drop the legacy ed25519 key parser
    • Dropped the legacy-ed25519-pkcs8-parser feature. Legacy keys were written in non-compliant format by russh pre-v0.43. From now on, parsing those keys will return a hard error.

Security fixes

GHSA-j7h2-66j4-ghjf - russh server accepts pubkey authentication with a mismatched signature algorithm

Russh server side did not verify that the client signatures were made using the negotiated algorithm. While no bypass is possible through this bug, this allowed a client to e.g. silently downgrade its own signature from rsa-sha2-512 to rsa-sha1

Features

  • efa9a03: Add support hostkeys-prove-00@openssh.com support (#767) (@​inureyes) #767

    • Adds client::Handle::hostkeys_prove to ask the server to prove ownership of the host keys it announced via hostkeys-00@openssh.com.
  • a0ded76: Support sending custom global requests from the client (#759) (@​ChrisJr404) #759

    • Adds client::Handle::send_global_request(name, data, want_reply)

Fixes

New Contributors

Full Changelog: Eugeny/russh@v0.63.3...v0.64.0

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: agent, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🔒 Supply Chain Security Review

Check Status
Socket.dev malware scan ✅ success
Vulnerability audit ✅ success
Lockfile diff review ✅ success
OSSF Scorecard ✅ success

This review was automatically generated by the Supply Chain Review workflow.

Bumps the rust-major group with 1 update in the /catalyst-agent directory: [russh](https://github.com/warp-tech/russh).


Updates `russh` from 0.63.3 to 0.64.1
- [Release notes](https://github.com/warp-tech/russh/releases)
- [Commits](Eugeny/russh@v0.63.3...v0.64.1)

---
updated-dependencies:
- dependency-name: russh
  dependency-version: 0.64.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(agent)(deps): bump russh from 0.63.3 to 0.64.1 in /catalyst-agent in the rust-major group chore(agent)(deps): bump russh from 0.63.3 to 0.64.1 in /catalyst-agent in the rust-major group across 1 directory Oct 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/catalyst-agent/rust-major-db36a3918a branch from 97933a2 to a492a10 Compare October 10, 2026 05:01
@github-actions

Copy link
Copy Markdown
Contributor

🔒 Supply Chain Security Review

Check Status
Socket.dev malware scan ✅ success
Vulnerability audit ✅ success
Lockfile diff review ✅ success
OSSF Scorecard ✅ success

This review was automatically generated by the Supply Chain Review workflow.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants