Skip to content

fix(deps): patch the rustls TLS 1.3 advisory (RUSTSEC-2026-0285) - #728

Merged
EVWorth merged 1 commit into
mainfrom
fix/rustls-advisory
Sep 24, 2026
Merged

EVWorth merged 1 commit into
mainfrom
fix/rustls-advisory

Conversation

@EVWorth

@EVWorth EVWorth commented Sep 23, 2026

Copy link
Copy Markdown
Owner
rustls 0.23.42 → 0.23.45
TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries

1.1.0 shipped with this. rustls reaches us through the updater's HTTPS
client and through sqlx's TLS — so it's on the path that fetches releases and
the path that talks to a database over TLS.

0.23.45 is the minimum patched release and is 9 days old, clearing the
seven-day publish-age rule.

After: the rustls advisory is gone. The two remaining are the quick-xml pair
already on the known-accepted list, blocked on a wayland-rs release (#206).

How this was nearly missed, twice

It surfaced on dependabot PR #725, and my first instinct was that the bump had
introduced it — main looked clean when I checked. It wasn't. Two separate
things hid it:

scripts/cargo-audit-check.sh needs jq. Without it the parse fails, the
failure is printed, and the script still exits 0. A gate that reports
success when it couldn't read its input is worse than no gate, because it gets
believed. CI has jq so CI was right all along — but the script exists to be run
locally, which is precisely where this bites.

cargo audit uses a cached advisory database. Mine was stale, so even a
working parse would have said clean. The advisory postdates my last fetch.

So the first reading was wrong in the usual direction: the new thing looked
guilty, the old thing looked fine. Re-checking main with a fresh database is
what settled it.

I'd suggest a follow-up to make that script fail loudly when jq is missing —
filing separately rather than widening this one.

Verification

  • cargo audit: 0 hits for RUSTSEC-2026-0285
  • cargo clippy --workspace --all-targets --all-features clean
  • just test-rust green

🤖 Generated with Claude Code

    rustls 0.23.42 → 0.23.45
    TLS 1.3 handshake messages incorrectly accepted across encryption
    level boundaries

1.1.0 shipped with this. It reaches us through the updater's HTTPS client and
through sqlx's TLS, so it is on the path that fetches releases and the path
that talks to a server over TLS.

0.23.45 is the minimum patched release and is nine days old, so it clears the
seven-day publish-age rule this project holds dependencies to.

Worth recording how this was nearly missed twice.

It surfaced on a dependabot PR, and my first instinct was that the bump had
introduced it — main looked clean when I checked. It was not clean. Two
separate things hid it:

`scripts/cargo-audit-check.sh` needs `jq`, and in an environment without it the
parse fails, the failure is printed but not fatal, and the script exits 0. A
gate that reports success when it could not read its input is worse than no
gate, because it is believed. That is not CI's problem — CI has jq — but it is
anyone's problem who runs the script locally, which is what it is for.

And `cargo audit` uses a cached advisory database. Mine was stale, so even a
working parse would have said clean. The advisory was published after my last
fetch.

So the first reading was wrong in the usual direction: the new thing looked
guilty and the old thing looked fine. Checking main with a fresh database is
what settled it.
@EVWorth
EVWorth merged commit 824df3d into main Sep 24, 2026
12 checks passed
@EVWorth
EVWorth deleted the fix/rustls-advisory branch September 24, 2026 10:57
@EVWorth EVWorth mentioned this pull request Oct 5, 2026
EVWorth added a commit that referenced this pull request Oct 5, 2026
Version bump across the three manifests and the two lockfile entries
that record the app's own version.

What 1.2.0 contains since 1.1.0:

- Each editor tab runs on its own server session, so SET @var,
  temporary tables and multi-run transactions carry across runs (#734)
- Separate connection lanes for the agent and for backups/restores, so
  neither can starve the editor; the pool-exhausted message says what
  is holding the pool (#732, #727)
- Copy button beside Expand for long cell values, such as SHOW CREATE
  TABLE (#748)
- Linux/Wayland: WebKitGTK's DMABUF renderer is turned off, for the
  black area left after resizing the window (#742)
- Tauri 2.12 on both the npm and Rust sides (#749), and the dependency
  roll-up in #740
- rustls TLS 1.3 advisory RUSTSEC-2026-0285 patched (#728)

Also the first release built with rustup in place of
dtolnay/rust-toolchain (#746), so the release jobs' toolchain step runs
on Windows and macOS for the first time.


Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant