Skip to content

Bump rustls from 0.23.37 to 0.23.45 - #1003

Merged
Mikola Lysenko (mikolalysenko) merged 5 commits into
mainfrom
dependabot/cargo/rustls-0.23.45
Oct 8, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 5 commits into
mainfrom
dependabot/cargo/rustls-0.23.45

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps rustls from 0.23.37 to 0.23.45.

Commits
  • 2976d90 Prepare 0.23.45
  • f9d4ee9 Handshake "alignment" check covers previously-received messages
  • c4e92e8 Keep data needed for HRR processing together
  • e553a7a server: TLS1.2 is not available after a HRR
  • 5dff9da Test whether server negotiates TLS1.2 after HRR
  • 185a063 reject a second ClientHello that changes the cipher suite
  • 9fafe6d reject a second ClientHello that drops pre_shared_key
  • 1b42c5f providers: zeroize private key DER
  • 64ad386 Bump version to 0.23.44
  • 1efbf66 bogo: remove PostQuantum setup
  • Additional commits viewable in compare view

```''````''`````''``````''```````''````````''[[Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=rustls&package-manager=cargo&previous-version=0.23.37&new-version=0.23.45)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)'''''''''''''''''''''''''''''''''''''''''''''

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting ·@·d·ependabot r·ebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • ·@·d·ependabot r·ebase will rebase this PR
  • ·@·d·ependabot r·ecreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • ·@·d·ependabot i·gnore t·his major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • ·@·d·ependabot i·gnore t·his minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • ·@·d·ependabot i·gnore t·his dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Generated by Claude Code

Bumps [rustls](https://github.com/rustls/rustls) from 0.23.37 to 0.23.45.
- [Release notes](https://github.com/rustls/rustls/releases)
- [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md)
- [Commits](rustls/rustls@v/0.23.37...v/0.23.45)

---
updated-dependencies:
- dependency-name: rustls
  dependency-version: 0.23.45
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator

bugbot run


Generated by Claude Code

@cursor

cursor Bot commented Oct 7, 2026

Copy link
Copy Markdown

Bugbot couldn't run

Bugbot is not enabled for your user on this team.

Ask your team administrator to increase your team's hard limit for Bugbot seats or add you to the allowlist in the Cursor dashboard.

@mikolalysenko

Copy link
Copy Markdown
Collaborator

bugbot run


Generated by Claude Code

@cursor

cursor Bot commented Oct 7, 2026

Copy link
Copy Markdown

Bugbot couldn't run

Bugbot is not enabled for your user on this team.

Ask your team administrator to increase your team's hard limit for Bugbot seats or add you to the allowlist in the Cursor dashboard.

@mikolalysenko

Copy link
Copy Markdown
Collaborator

bugbot run


Generated by Claude Code

@cursor

cursor Bot commented Oct 7, 2026

Copy link
Copy Markdown

Bugbot couldn't run

Bugbot is not enabled for your user on this team.

Ask your team administrator to increase your team's hard limit for Bugbot seats or add you to the allowlist in the Cursor dashboard.

@mikolalysenko

Copy link
Copy Markdown
Collaborator

bugbot run


Generated by Claude Code

@cursor

cursor Bot commented Oct 7, 2026

Copy link
Copy Markdown

Bugbot couldn't run

Bugbot is not enabled for your user on this team.

Ask your team administrator to increase your team's hard limit for Bugbot seats or add you to the allowlist in the Cursor dashboard.

@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 7, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Oct 7, 2026
@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 7, 2026
@mikolalysenko

Mikola Lysenko (mikolalysenko) commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

[agent] Ready for review at 4b789e0eee38762301dba55743ca8766cf84448c.

  • CI: required ci-ok green. 451 success / 7 skipped / 0 failing of 480 check runs. 22 non-required macOS/Windows native / install-proof legs are still queued on the runner backlog.
  • Bugbot: not available for Dependabot PRs; no open review threads.
  • Mergeable, no conflicts.
  • Bugbot can't review Dependabot PRs (seat not enabled for the bot author); lockfile-only bump of rustls 0.23.37 → 0.23.45.

Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit 05fd82b Oct 8, 2026
480 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the dependabot/cargo/rustls-0.23.45 branch October 8, 2026 04:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants