release: 0.13.1 - #48
Merged
Merged
Conversation
rustls 0.23.40 is flagged by RUSTSEC-2026-0285: TLS 1.3 handshake messages were incorrectly accepted across encryption level boundaries. Fixed upstream in 0.23.45. Severity is Medium (5.3). rustls is the TLS stack reqwest uses for every https:// target, so the flaw is reachable from a hostile target server during the handshake. The daily security audit has been failing since 2026-09-25 as a result. A plain `cargo update -p rustls` stops at 0.23.43, which is still affected, because 0.23.45 needs newer rustls-webpki (0.103.15) and aws-lc-rs (1.18.1, with aws-lc-sys 0.45.0, which adds pkg-config as a build dependency). Pin precisely so those move together. cargo audit and cargo deny are clean. Lockfile-only change; no driller source is affected and the full test suite passes unchanged.
Run `cargo update` across the lockfile (175 package changes). No Cargo.toml requirement changes were needed: every direct dependency's latest release is already within its declared range, and cargo outdated reports no major-version gaps. Notable direct bumps: tokio 1.53.2, reqwest 0.13.5, clap 4.6.7, regex 1.13.1, hdrhistogram 7.6.0, rand 0.10.3, serde_json 1.0.151, thiserror 2.0.21. Several duplicate transitive versions (getrandom, hashbrown, foldhash, anyhow) drop out of the graph, and the yanked chacha20 0.10.0 is replaced by 0.10.2, which clears the last cargo audit warning. cargo audit, cargo deny, fmt, clippy -D warnings, the full test suite and a release build all pass.
Cut 0.13.1 from the work merged since 0.13.0: the RUSTSEC-2026-0258 (h2) and RUSTSEC-2026-0285 (rustls) fixes, the classified failed-request output, the thiserror-derived library Error, the dependency refresh, and the project website. Patch rather than minor: no public library item changed since 0.13.0, and every CLI flag and plan file is unchanged. - Cargo.toml / Cargo.lock: 0.13.0 -> 0.13.1 - CHANGELOG: roll [Unreleased] into [0.13.1] (2026-10-04), refresh compare links
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cut 0.13.1. This is stacked on #47; once #47 merges, rebase onto
mainand retarget.Patch rather than minor: no public library items changed since 0.13.0, and every CLI flag and plan file is unchanged. The release contains:
h20.4.19 (RUSTSEC-2026-0258) andrustls0.23.45 (RUSTSEC-2026-0285), both on the request pathERR <cause>line (full cause chain under--verbose); the libraryErrornow derives viathiserror(identical API); dependencies refreshedChanges in this PR:
Cargo.toml/Cargo.lock: 0.13.0 -> 0.13.1CHANGELOG.md: roll[Unreleased]into[0.13.1](2026-10-04) and refresh the compare linksAfter merge: tag
0.13.1and publish the GitHub Release, which triggersrelease.ymlto build the binaries.