Skip to content

fix: upgrade aws-lc-sys to 0.39.0 (GHSA-394x-vwmw-crm3)#53358

Open
orbisai0security wants to merge 2 commits intozed-industries:mainfrom
orbisai0security:fix-ghsa-394x-vwmw-crm3-cargo-lock
Open

fix: upgrade aws-lc-sys to 0.39.0 (GHSA-394x-vwmw-crm3)#53358
orbisai0security wants to merge 2 commits intozed-industries:mainfrom
orbisai0security:fix-ghsa-394x-vwmw-crm3-cargo-lock

Conversation

@orbisai0security
Copy link
Copy Markdown

Summary

Upgrade aws-lc-sys from 0.37.0 to 0.39.0 to fix GHSA-394x-vwmw-crm3.

Vulnerability

Field Value
ID GHSA-394x-vwmw-crm3
Severity HIGH
Scanner trivy
Rule GHSA-394x-vwmw-crm3
File Cargo.lock

Description: AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

Changes

  • Cargo.lock
  • Cargo.toml

Verification

  • Build passes
  • Scanner re-scan confirms fix
  • LLM code review passed

Automated security fix by OrbisAI Security

Ubuntu and others added 2 commits April 8, 2026 03:39
@cla-bot
Copy link
Copy Markdown

cla-bot bot commented Apr 8, 2026

Thank you for your pull request and welcome to our community. We could not parse the GitHub identity of the following contributors: Ubuntu.
This is most likely caused by a git client misconfiguration; please make sure to:

  1. check if your git client is configured with an email to sign commits git config --list | grep email
  2. If not, set it up using git config --global user.email email@example.com
  3. Make sure that the git commit email is configured in your GitHub account settings, see https://github.com/settings/emails

@zed-community-bot zed-community-bot bot added the first contribution the author's first pull request to Zed. NOTE: the label application is automated via github actions label Apr 8, 2026
@zed-codeowner-coordinator zed-codeowner-coordinator bot requested a review from a team April 8, 2026 03:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

first contribution the author's first pull request to Zed. NOTE: the label application is automated via github actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant