Skip to content

fix(deps): update aws-lc-sys to 0.38.0 for security fixes#77

Merged
bug-ops merged 1 commit intomainfrom
fix/aws-lc-sys-security
Mar 4, 2026
Merged

fix(deps): update aws-lc-sys to 0.38.0 for security fixes#77
bug-ops merged 1 commit intomainfrom
fix/aws-lc-sys-security

Conversation

@bug-ops
Copy link
Owner

@bug-ops bug-ops commented Mar 4, 2026

Summary

  • Update aws-lc-rs 1.15.4 -> 1.16.1 (aws-lc-sys 0.37.1 -> 0.38.0)
  • Resolves 3 high-severity Dependabot alerts:

Test plan

  • cargo +nightly fmt --check passes
  • cargo clippy --workspace --all-targets --all-features -- -D warnings passes
  • cargo nextest run — 1247 tests passed

Update aws-lc-rs 1.15.4 -> 1.16.1 (aws-lc-sys 0.37.1 -> 0.38.0)
to fix three high-severity vulnerabilities:
- GHSA-hfpc-8r3f-gw53: PKCS7_verify Signature Validation Bypass
- GHSA-65p9-r9h6-22vj: Timing Side-Channel in AES-CCM Tag Verification
- GHSA-vw5v-4f2q-w9xf: PKCS7_verify Certificate Chain Validation Bypass
@github-actions github-actions bot added rust Rust code changes needs-review Needs review size: XS <10 lines changed labels Mar 4, 2026
@bug-ops bug-ops enabled auto-merge (squash) March 4, 2026 19:55
@bug-ops bug-ops disabled auto-merge March 4, 2026 19:59
@bug-ops bug-ops merged commit 757db07 into main Mar 4, 2026
19 checks passed
@bug-ops bug-ops deleted the fix/aws-lc-sys-security branch March 4, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review Needs review rust Rust code changes size: XS <10 lines changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant