Update rustls to 0.23.45 for RUSTSEC-2026-0285

rustls 0.23.43 accepted TLS 1.3 handshake messages across encryption
level boundaries. It is the TLS client behind the Nostr relay
connections, so every default build reached it. The update is a
lockfile change within the version range the dependencies already
allow, and the changelog records it under Security.
This commit is contained in:
Johnathan Corgan
2026-09-28 15:31:24 +00:00
parent 299df5ad19
commit df358f69ea
2 changed files with 10 additions and 2 deletions
+8
View File
@@ -546,6 +546,14 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
request, since that names an event the routing key signed itself. The request, since that names an event the routing key signed itself. The
discovery and traversal design documents describe the new behaviour. discovery and traversal design documents describe the new behaviour.
#### Dependencies
- The lockfile moves `rustls` from 0.23.43 to 0.23.45, for RUSTSEC-2026-0285:
0.23.43 accepted TLS 1.3 handshake messages across encryption-level
boundaries. It is the TLS client the Nostr relay connections use, so every
default build reached it. The update is within the version range the
dependencies already allowed.
## [0.5.1] - 2026-09-06 ## [0.5.1] - 2026-09-06
### Fixed ### Fixed
Generated
+2 -2
View File
@@ -2960,9 +2960,9 @@ dependencies = [
[[package]] [[package]]
name = "rustls" name = "rustls"
version = "0.23.43" version = "0.23.45"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0283386ce02abc0151e1761d08802dfe86c173b0b494af5cbc086574e453da06" checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634"
dependencies = [ dependencies = [
"once_cell", "once_cell",
"ring", "ring",