Skip to content

fix(deps): patch compatible Rust transport dependencies - #32

Draft
anandpant wants to merge 1 commit into
mainfrom
codex/security-rust-transport-2026-10-07
Draft

anandpant wants to merge 1 commit into
mainfrom
codex/security-rust-transport-2026-10-07

Conversation

@anandpant

Copy link
Copy Markdown
Contributor

Summary

Refresh the compatible locked dependency lines without changing application APIs or workspace dependency declarations:

  • aws-smithy-json 0.62.5 → 0.62.7 (and required Smithy runtime/types/schema closure)
  • quinn-proto 0.11.14 → 0.11.15
  • rustls 0.23.38 → 0.23.45, rustls-webpki 0.103.12 → 0.103.15 and required AWS-LC closure
  • h2 0.4.13 → 0.4.16

Cargo regenerated the lockfile and selected package checksums; no hand-edited resolution data.

Security

Covers compatible fixes for Smithy JSON recursion, Quinn reassembly exhaustion, Rustls handshake boundaries, WebPKI CRL parsing and HTTP/2 empty DATA frames.

This is a partial, compatible remediation. The older rustls-webpki 0.101.7/rustls 0.21 and h2 0.3 lines remain through aws-smithy-http-client; removing them needs a separate AWS client/feature migration. Parquet's older thrift/lru and the paste maintenance warning also remain. No claim of zero vulnerabilities or verified exploit reachability.

Validation

Passed locally on Rust 1.99.0:

  • cargo check --workspace --locked
  • cargo test --workspace --locked: 28 tests passed, all doc-test targets passed
  • Reverse dependency inspection for retained legacy TLS/HTTP/Parquet lines
  • git diff --check

No live Convex, AWS/S3 or Databricks operations performed. Draft pending hosted checks and review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant