Skip to content

release: 0.13.1 - #48

Merged
zoosky merged 4 commits into
mainfrom
release/0.13.1
Oct 4, 2026
Merged

zoosky merged 4 commits into
mainfrom
release/0.13.1

Conversation

@zoosky

@zoosky zoosky commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Cut 0.13.1. This is stacked on #47; once #47 merges, rebase onto main and retarget.

Patch rather than minor: no public library items changed since 0.13.0, and every CLI flag and plan file is unchanged. The release contains:

  • Security: h2 0.4.19 (RUSTSEC-2026-0258) and rustls 0.23.45 (RUSTSEC-2026-0285), both on the request path
  • Changed: failed requests print a concise classified ERR <cause> line (full cause chain under --verbose); the library Error now derives via thiserror (identical API); dependencies refreshed
  • Added: project website at https://zoosky.github.io/driller

Changes in this PR:

  • Cargo.toml / Cargo.lock: 0.13.0 -> 0.13.1
  • CHANGELOG.md: roll [Unreleased] into [0.13.1] (2026-10-04) and refresh the compare links

After merge: tag 0.13.1 and publish the GitHub Release, which triggers release.yml to build the binaries.

zoosky added 3 commits October 4, 2026 09:44
rustls 0.23.40 is flagged by RUSTSEC-2026-0285: TLS 1.3 handshake
messages were incorrectly accepted across encryption level boundaries.
Fixed upstream in 0.23.45. Severity is Medium (5.3).

rustls is the TLS stack reqwest uses for every https:// target, so the
flaw is reachable from a hostile target server during the handshake.
The daily security audit has been failing since 2026-09-25 as a result.

A plain `cargo update -p rustls` stops at 0.23.43, which is still
affected, because 0.23.45 needs newer rustls-webpki (0.103.15) and
aws-lc-rs (1.18.1, with aws-lc-sys 0.45.0, which adds pkg-config as a
build dependency). Pin precisely so those move together. cargo audit
and cargo deny are clean. Lockfile-only change; no driller source is
affected and the full test suite passes unchanged.
Run `cargo update` across the lockfile (175 package changes). No
Cargo.toml requirement changes were needed: every direct dependency's
latest release is already within its declared range, and cargo outdated
reports no major-version gaps.

Notable direct bumps: tokio 1.53.2, reqwest 0.13.5, clap 4.6.7,
regex 1.13.1, hdrhistogram 7.6.0, rand 0.10.3, serde_json 1.0.151,
thiserror 2.0.21. Several duplicate transitive versions (getrandom,
hashbrown, foldhash, anyhow) drop out of the graph, and the yanked
chacha20 0.10.0 is replaced by 0.10.2, which clears the last cargo audit
warning.

cargo audit, cargo deny, fmt, clippy -D warnings, the full test suite
and a release build all pass.
Cut 0.13.1 from the work merged since 0.13.0: the RUSTSEC-2026-0258
(h2) and RUSTSEC-2026-0285 (rustls) fixes, the classified failed-request
output, the thiserror-derived library Error, the dependency refresh, and
the project website. Patch rather than minor: no public library item
changed since 0.13.0, and every CLI flag and plan file is unchanged.

- Cargo.toml / Cargo.lock: 0.13.0 -> 0.13.1
- CHANGELOG: roll [Unreleased] into [0.13.1] (2026-10-04), refresh
  compare links
Base automatically changed from fix/rustls-rustsec-2026-0285 to main October 4, 2026 07:51
@zoosky
zoosky marked this pull request as ready for review October 4, 2026 07:56
@zoosky
zoosky merged commit f4d539c into main Oct 4, 2026
16 checks passed
@zoosky
zoosky deleted the release/0.13.1 branch October 4, 2026 07:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant