chore: Enforce min rustls version to 0.23.19
`rustls` versions 0.23.18 and 0.23.19 contains fix for vulnerability RUSTSEC-2024-0399. However, 0.23.18 bumps MSRV to 1.71. 0.23.19 reverts MSRV back to 1.63. We enforce min `rustls` version to 0.23.19 to make it easier to compile on MSRV and ensure we include the RUSTSEC-2024-0399 fix. Note that in CI, I decided to pin `rustls` dependency to 0.23.19 explicitly. This is because in future versions of `rustls`, the MSRV will be changed to 1.71.
This commit is contained in:
parent
f00b9998d1
commit
7ef3ff6873
2
.github/workflows/cont_integration.yml
vendored
2
.github/workflows/cont_integration.yml
vendored
@ -31,7 +31,7 @@ jobs:
|
||||
- name: Pin dependencies for MSRV
|
||||
if: matrix.rust == '1.63.0'
|
||||
run: |
|
||||
cargo update -p rustls --precise "0.23.17"
|
||||
cargo update -p rustls --precise "0.23.19"
|
||||
- name: Test
|
||||
run: cargo test --verbose --all-features
|
||||
- name: Setup iptables for the timeout test
|
||||
|
||||
@ -26,7 +26,7 @@ serde_json = { version = "^1.0" }
|
||||
|
||||
# Optional dependencies
|
||||
openssl = { version = "0.10", optional = true }
|
||||
rustls = { version = "0.23", optional = true, default-features = false }
|
||||
rustls = { version = "0.23.19", optional = true, default-features = false }
|
||||
webpki-roots = { version = "0.25", optional = true }
|
||||
|
||||
byteorder = { version = "1.0", optional = true }
|
||||
|
||||
Loading…
Reference in New Issue
Block a user